Usable with caveats: the package is licensed, documented, tested, and not archived, but its last registry release was nearly four years ago and recent repository activity is absent. A single publisher and no security policy add maintenance risk.
55%
Total Score
50
100
78
88
There have been only four releases, all concentrated in November 2022, with no release in nearly four years. That is a meaningful sign of stagnation for a dependency expected to receive compatibility and maintenance updates.
The repository had no commits and no active maintainers in the last three months, consistent with a project whose registry releases have stopped and increasing abandonment risk.
Only one registry account has publishing access, creating limited release continuity if that maintainer becomes unavailable. The repository is user-owned, so there is no organization backing shown to compensate for the thin publisher base.
The repository has no stars or forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide little evidence of a broad community that could sustain the project.
Composer is used as the build tool, but no security scanning tool is configured. The missing scanning is a transparency and maintenance gap, not evidence that the package is malicious.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version 6.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.