The MIT license, included tests, and stable major version make the package straightforward to inspect and integrate. However, it has had no registry release since August 2019 and no recent repository commits, while the README is only 28 characters. The repository also does not clearly identify the package, lowering maintenance and ownership confidence.
38%
Total Score
50
75
50
Only two releases exist, with the latest in August 2019 and none in the past 12 months. That long release gap is strong evidence of abandonment for an API library.
The repository has recorded zero commits and zero active maintainers in the last three months, consistent with the multi-year release gap. The project is not archived, but its observed maintenance activity has stopped.
The repository name does not match the package name and its README does not mention the package. That makes the source relationship and ownership less transparent.
Composer is used as the build tool, but no security scanning tools are present. This is a modest repository hygiene gap alongside the stronger maintenance concerns.
The linked repository has no security policy. This is a transparency gap for a package that exposes API integrations, though it does not by itself show unsafe behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.