Consumers get no README, tests, or changelog, making integration and verification harder. The package is also a very small, lightly supported client with no security scanning or policy.
15%
Total Score
0
40
50
This package has only one release, 0.0.1, published about 8 years ago, with no releases in the last 12 months. That leaves no evidence of ongoing maintenance or compatibility updates.
There were 0 commits and 0 active maintainers in the last 3 months, consistent with the repository's archived state and providing no current maintenance capacity.
The linked repository is archived and was last pushed about 8 years ago. An archived source project is a severe abandonment risk for a dependency.
The package contains no README, tests, or changelog, so consumers have little integration guidance or verification material. The tiny four-file artifact explains some of the minimalism but does not compensate for the lack of documentation and tests.
Composer is used for build and dependency management, which is appropriate, but no security-scanning tools are present. For an old, unmaintained dependency, the missing scanning provides no additional assurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version 6.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.