The repository is small but includes tests, release notes, and a clear package match. Maintenance has stopped since January 2025, while the license mismatch and workflow finding add avoidable adoption risk.
62%
Total Score
50
72
83
The artifact contains a license file and the repository also has one, so licensing is not absent. However, the manifest declares BSD-3-Clause while the detected license text is MIT, creating a clarity concern.
The package and repository are owned by an individual account rather than an organization, so the small maintainer and popularity footprint offers limited visible backing.
The package has 10 releases over roughly three years, but none in the last 12 months; the latest release was published in January 2025. This indicates a meaningful maintenance slowdown for a still pre-1.0 library.
There were no commits and no active maintainers in the last three months. Combined with no registry releases in the last year, this is the strongest maintenance concern.
The repository has 1 star, 1 fork, and 1 watcher, showing a very small user and contributor footprint. Low popularity is supporting evidence rather than a health verdict, but it leaves little visible resilience if maintenance stops.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 | — | — |
guzzlehttp/guzzle Version ^6.0 || ^7.0 | — | — |
kamermans/guzzle-oauth2-subscriber Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.