The generated client includes a substantial README, repository tests, a declared Unlicense, and no install-time scripts. Its dependencies are modest and the repository matches the package, but these positives do not offset the project’s inactive status.
12%
Total Score
0
100
50
75
Packagist marks the entire package as abandoned, with no replacement identified. Package-level deprecation is a direct warning against taking a new dependency on this release.
The latest release was in May 2023, and there were no releases in the preceding 12 months. That is over three years without a registry release and strongly indicates abandonment.
The repository had zero commits and zero active maintainers in the three-month measurement window. This provides no evidence of ongoing maintenance capacity.
The linked repository is archived, indicating the source project is no longer intended for normal maintenance. The recorded push in September 2025 does not compensate for its archived state.
The repository has no security policy or documented security contact. This weakens disclosure transparency, although the package’s deprecation and archived repository are the more serious concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.