The codebase has no tests or security scanning, and its last update was about ten years ago. Organization backing, a focused file tree, and clear usage documentation provide limited reassurance, but do not offset the abandonment risk.
38%
Total Score
100
67
75
The latest release was in March 2016, with no releases in the last 12 months despite the package being about ten years old. This is strong evidence of abandonment risk.
The package includes a useful README, while the absence of tests and a changelog is normal for published artifacts; however, the linked repository also reports no tests, reducing maintenance confidence for a library.
The repository has zero stars and forks and only two watchers. Popularity is not decisive, but these very low adoption signals provide no supporting evidence of an active project.
Composer is used for builds, which is appropriate, but no security scanning tooling is present. For an old dependency, this leaves an important maintenance and transparency gap.
The repository is not archived, which avoids a severe lifecycle warning, but it was last pushed in March 2016 and therefore provides little evidence of current maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.