The MIT declaration, matching repository, organization backing, and absence of install scripts provide some reassurance. The package remains a very small, undocumented library with no recent maintenance or security policy, so pinning it creates substantial abandonment risk.
35%
Total Score
50
100
56
67
The latest release was in October 2016, with no releases in the last 12 months; this is strong evidence of abandonment despite the package having three historical releases.
There were zero commits and zero active maintainers in the last three months, consistent with a project that has been inactive for years.
The package and repository contain only three files, including one source file and the manifest. This may be intentional for a tiny SDK, but it provides little visible documentation or project depth.
The artifact has no README, while tests and a changelog are normal repository concerns and are not expected in every published package. For an SDK library, the missing README reduces consumer transparency.
The repository has zero stars and forks and one watcher. Low popularity is supporting evidence rather than a verdict, but it offers little evidence of broad community support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.