The package is straightforward to consume and has a clear MIT license, README, and release notes. Its organization-backed repository remains active, but maintenance depends on a single recent contributor and there is no security policy.
68%
Total Score
67
100
86
75
The package has existed since 2020 but has only four releases, with a median interval of about 636 days; one release in the last 12 months shows it is not abandoned, but cadence is slow.
All three-month commit activity came from one contributor. Organization ownership provides some handoff capacity, but no second recently active contributor is shown.
Only one commit was recorded in the last three months, so recent activity is limited even though it aligns with the latest release.
Composer is used for builds, but no security-scanning tool is configured, leaving a modest transparency and maintenance gap.
The repository has no security policy, making vulnerability reporting and response expectations less clear for users.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.0 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.