Tests, a README, Apache-2.0 licensing, and a clean workflow audit support routine use. The missing security policy and narrow active contribution base leave more maintenance risk than a mature dependency should carry.
65%
Total Score
75
88
75
The package has 17 releases since July 2022, but none in the last 12 months; the resulting release inactivity is a maintenance concern despite the earlier regular cadence.
All recent commits came from one contributor. Organization backing provides some handoff capacity, but no second active contributor is shown in this period.
Only one commit was recorded in the last three months, with one active maintainer, indicating very limited recent development activity.
Composer is used for builds, but no security-scanning tool is detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, making vulnerability reporting and response expectations less clear for consumers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7.0|^2.0 | — | — |
guzzlehttp/guzzle Version ^7.4 | — | — |
laravel/framework Version >=9 <12 | — | — |
guzzlehttp/promises Version ^1.4.0 | — | — |
php-http/guzzle7-adapter Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.