The package has a clear README, a stable release, and a small dependency surface. Its organization-owned repository is intact, but no commits or releases have appeared for about three years and no security policy is published.
55%
Total Score
50
100
83
83
There were no commits and no active maintainers in the last three months, consistent with the roughly three-year gap since the last release. This materially raises maintenance and abandonment risk.
Only two releases exist, with the latest published about three years ago and none in the last 12 months. This indicates prolonged inactivity, although it does not by itself show abandonment.
The repository has 24 stars, one fork, and no watchers, indicating limited community support. Popularity is supporting evidence rather than a decisive health verdict.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning coverage is a modest transparency and maintenance gap.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.