Usable with caveats: the package is licensed, documented, tested, and backed by an organization, but it has only one release in 61 days and minimal repository activity from a single contributor. The lack of a security policy adds a transparency gap for a young dependency.
68%
Total Score
67
100
88
83
This is a young package with one release over 61 days and no established release cadence, so long-term maintenance is not yet demonstrated.
All recent activity comes from one contributor, creating a thin maintenance base; organization backing provides some capacity to hand off work but no second active contributor is shown.
Only one commit was recorded in the last three months, which is limited evidence of ongoing maintenance for a package intended as an SDK.
Composer build tooling is present, but no security scanning tools were detected; for this young SDK, that leaves a modest process gap.
No repository security policy was found, reducing transparency about how vulnerabilities would be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.