The package has seen no release since February 2016, and the repository has been inactive since November 2018. Its MIT declaration, matching repository, and small dependency set help, but six open issues, no tests, and no security policy leave maintenance risk unresolved.
38%
Total Score
50
100
64
75
Only two releases were published, with the latest in February 2016 and none in the last 12 months. This long release gap is strong evidence of abandonment risk.
The artifact includes a README, but it is only 14 characters long and neither the package nor repository reports tests or a changelog. Missing tests and changelogs are expected packaging practice, while the extremely limited README is a minor transparency gap for a library.
Six issues remain open, with no new or closed issues and no pull-request activity in the last month. Combined with the stale release history, this suggests unresolved maintenance demand.
Composer is used for the build, but no security-scanning tools are reported. This is a modest hygiene gap rather than a severe risk, especially given the package's very small dependency profile.
The repository is not archived, which is a positive counter-signal, but it was last pushed in November 2018 and has been inactive for years. That substantially weakens confidence in ongoing maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.