It has a long release history, a stable major version, clear documentation, and organization backing. The main concern is that repository activity has stopped recently, with no commits or issue movement in the latest three months.
68%
Total Score
75
100
88
75
The package has existed for about 11 years with 40 releases and a latest release on January 8, 2026. Only one release in the last 12 months indicates a slower current cadence, but the exact version is recently published.
The repository has zero commits and zero active maintainers in the latest three months. With only one release in the last year, this materially lowers confidence in ongoing maintenance.
There is only one open issue and two open pull requests, but no new or closed issues and no merged pull requests in the latest three months. This suggests little current maintenance activity.
Composer is used as the build tool, but no security scanning tools are present. That is a maintenance and assurance gap, though it is not evidence that the release is unsafe by itself.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear for a client handling API credentials.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0|~7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.