The repository is small and has no security scanning or security policy. Its MIT license, matching repository, and installation documentation provide useful transparency, but not enough ongoing maintenance evidence.
38%
Total Score
50
100
72
83
The package has only 3 releases, with the latest published over seven years ago and none in the last 12 months. This is strong evidence of an abandoned release line.
There were zero commits and zero active maintainers in the last three months, consistent with the repository having been inactive for over seven years.
The repository has zero stars, forks, and watchers, so there is no visible community adoption signal to offset the lack of maintenance activity.
Composer build tooling is present, but no security scanning tools are configured. This is a maintenance and security-hygiene gap, though not evidence of malicious behavior.
The repository is not archived, but its last push was over seven years ago, so the unarchived status does not demonstrate active maintenance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.4 | — | — |
guzzlehttp/guzzle Version ^6.3.3 | — | — |
guzzlehttp/promises Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.