Risky to adopt: the package has been effectively abandoned, with its latest release and repository update more than six years ago. It is clearly licensed, has tests, and matches its source repository, but those strengths do not offset the lack of ongoing maintenance.
45%
Total Score
0
67
The package has only three releases, all clustered on July 28, 2020, with no releases in the last 12 months. This long period without a new release is a strong abandonment concern.
The repository had zero commits and zero active maintainers during the last three months. Combined with the old last push, this indicates no current maintenance capacity.
The repository is not marked archived, which is a positive sign, but its last push was on July 28, 2020. The unarchived status does not compensate for the prolonged inactivity.
The assessed release is v0.0.3 and is not a stable major release, indicating an immature version line. No prerelease labeling partly reduces the concern, but the low version remains a maturity gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version 6.*|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.