Its MIT license, simple dependency set, and matching source repository make the package easy to inspect. However, the project has had no commits or releases for about nine years, with no tests or security policy, so maintenance risk is substantial.
38%
Total Score
38
100
67
75
All three releases were published in September 2017, and there have been no releases in about nine years. The releases were clustered within hours, leaving no evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, matching the roughly nine-year gap since its last push and strongly indicating abandonment risk.
One registry maintainer is consistent with a small user-owned project, but the single-person publishing base offers limited visible redundancy when paired with the inactive repository.
A README and release notes for this version provide basic consumer and change context. The absence of tests and a changelog in the published artifact is normal, while repository test and changelog support are also absent.
The package and repository are owned by the same individual account, with no organization backing shown. That is coherent ownership but provides limited evidence of sustained project capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0 | — | — |
illuminate/support Version 5.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.