The repository is clearly tied to an organization, matches the package, and includes a changelog. It has no recent commit activity, tests, or security scanning, which limits confidence in ongoing maintenance.
58%
Total Score
75
100
83
83
The package has 11 releases over about 4 years, but none in the last 12 months and its latest release was October 2, 2024. That indicates a meaningful maintenance slowdown, though the project is not entirely new or abandoned by age alone.
There were zero commits and zero active maintainers in the last 3 months, consistent with the long gap since the October 2024 release and raising abandonment risk.
The repository has 2 stars and no forks, indicating limited external adoption. Popularity is only supporting evidence, so this modestly limits maturity confidence without determining the verdict.
Composer is used for the build, but no security-scanning tools are configured. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy. For an API client this is a transparency gap, although it does not by itself show that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6 || ^7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.