The package has a clear license and a matching source repository. Its README has unfinished usage and testing sections, and the project provides no security policy.
42%
Total Score
0
75
50
All three releases were clustered within about 20 minutes, and there have been no releases for about two years. This strongly suggests the package is no longer actively maintained.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the long release gap and raising abandonment risk.
The artifact includes a README, but its usage and testing sections still say TODO. Missing tests and a changelog are normal for a published artifact, so the unfinished consumer documentation is the meaningful gap.
The linked repository has no security policy. This is a modest transparency and maintenance gap, though it is less significant than the prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.