The package is licensed, tested in its source repository, and has documented release notes. Its maintenance has ended, with no recent commits or issue activity, leaving this integration dependent on an archived and abandoned release.
12%
Total Score
50
50
50
83
Packagist marks the entire package as abandoned, with no replacement named. Package-level abandonment is a severe warning for a new dependency.
The package has 32 releases over its history, but its latest release was in January 2017 and there were no releases in the last 12 months. The long release gap outweighs its earlier cadence.
The repository recorded zero commits and zero active maintainers in the last three months. This confirms that the project is not receiving ongoing maintenance.
The linked repository is archived, and its last push was in March 2017. Archived source indicates active maintenance has ended.
The package declares 15 runtime dependencies, including HTTP, authentication, and cache components. This is a substantial dependency surface for an old package and increases maintenance exposure, though it is not independently severe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.3 | — | — |
firebase/php-jwt Version 4.0.* | — | — |
php-http/httplug Version ^1.0 | — | — |
php-http/message Version ^1.3 | — | — |
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.