Organization backing, tests, documentation, and release notes provide useful support. No commits or releases have appeared for roughly two years, while all four CI actions are unpinned and no security policy or scanning is reported.
58%
Total Score
50
100
79
75
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the roughly two-year release gap and indicating stalled maintenance.
The package has only four releases, clustered over about one week, and none in the last 12 months; the latest release is roughly two years old. This indicates a real maintenance concern despite the package not being deprecated.
Composer build tooling is present, but no security-scanning tools are reported. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a network client library.
Version 0.2.2 is a stable, non-prerelease release, but the package remains below 1.0, so compatibility expectations are somewhat weaker than for a mature major release.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-message Version ^1.0 | — | — |
guzzlehttp/guzzle Version ^7.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.