Documentation and project safeguards are thin. The organization-backed source and stable, non-deprecated release provide useful reassurance, but the limited history and lack of recent commits make long-term maintenance uncertain.
57%
Total Score
75
100
79
83
The artifact has no README, tests, or changelog, and the linked project also reports no tests or changelog; the missing artifact tests and changelog are normal, but the missing consumer documentation weakens transparency.
The package is only 143 days old and all three releases arrived within roughly one day, leaving little evidence of an established maintenance pattern.
There were no commits and no active maintainers in the last three months, which is a concrete sign that maintenance may have stalled after the initial release burst.
The repository uses Composer, appropriate for this PHP package, but reports no security scanning tools, leaving a modest tooling gap.
The repository has no security policy, reducing transparency about how users should report vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.