The package includes a usable README, a clear nine-file source tree, and an MIT declaration. It has no security scanning and very little community activity, increasing the cost of relying on an old library.
38%
Total Score
25
50
72
83
Only one release exists, published more than eight years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a library dependency.
There were zero commits and zero active maintainers in the last three months. Combined with the old last release, this indicates a substantial abandonment risk.
The package declares eight runtime dependencies and no development dependencies. The dependency set is not excessive, but the absence of development dependencies provides little evidence of maintained testing or development practice.
The package and repository are owned by the same individual account, so there is no organization backing shown to compensate for the very small maintainer and contributor base.
The repository has one star, zero forks, and one watcher, providing very little independent adoption or community support.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.4 | — | — |
php-http/httplug Version ^1.1 | — | — |
psr/http-message Version ^1.0 | — | — |
php-http/discovery Version ^1.4 | — | — |
php-http/guzzle6-adapter Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.