Risky to depend on: this package has had only one release, published over four years ago, with no recent repository activity. It is small and clearly backed by a matching organization repository, but there is little evidence of ongoing maintenance or security oversight.
48%
Total Score
50
100
72
83
The package has only one release, v1.0.0, first published over four years ago, with no releases in the last 12 months. That strongly limits evidence of ongoing maintenance, although a small stable client can sometimes remain unchanged.
The repository recorded no commits and no active maintainers during the last three months, consistent with the package having been effectively inactive since its initial release. No provided signal shows recent maintenance to offset this.
The repository has zero stars and forks and only two watchers, providing little community visibility or supporting evidence. Low popularity alone is not decisive for a small API client.
Composer is used as the build tool, which is appropriate for the package, but no security scanning tools are reported. The repository's minimal tooling provides limited additional assurance.
The repository is not archived, which leaves the project technically maintainable, but its last push was over four years ago and does not offset the lack of current activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.