The package is small and clearly tied to its repository, with a stable 1.0 release and a simple dependency set. Its README says it is work in progress, and the repository has no tests or security policy.
52%
Total Score
50
100
78
83
Only one release has been published, on 28 May 2024, with no releases in the past 12 months; this is a substantial maintenance concern for a work-in-progress API client.
The repository has had no commits and no active maintainers in the past three months, reinforcing the risk that maintenance has stalled.
The repository has zero stars and only one fork, providing little community evidence; popularity is supporting evidence, so this modestly reinforces the maintenance concerns rather than deciding the verdict.
Composer is used for the build, but no security scanning tooling is present; this is a hygiene gap rather than evidence that the package is unsafe to depend on.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.0 | ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.