The generated client includes tests, a substantial README, and a stable 1.0.0 release. Its proprietary licensing, absent security policy, and lack of activity since January 2020 make long-term adoption risky.
42%
Total Score
0
100
50
83
The manifest declares a proprietary license, with no detected license text or license file. This limits transparency and may restrict dependable reuse compared with a clearly identified open-source license.
This package has only one release, published about 6 years and 8 months ago, with no releases in the last 12 months; that is strong evidence of abandonment risk.
There were zero commits and zero active maintainers in the last 3 months, consistent with the package's single-release history and materially increasing abandonment risk.
The repository name matches the package, but its README does not mention the package name, creating some uncertainty about package-specific ownership and release tracking.
Composer is used for builds, but no security scanning tools were detected, leaving a project-level hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.