The MIT license, focused dependency set, and matching repository make its provenance clear. The small codebase and release notes help explain the package, but the project provides no security policy or scanning.
58%
Total Score
75
100
78
75
The latest release was published in July 2021, with no releases in the last 12 months and a long median interval between releases. This is the strongest sign of a dormant dependency.
The repository recorded no commits and no active maintainers in the last three months, consistent with the release history showing that development has stopped for over five years.
The repository has only 2 stars, 3 forks, and 1 watcher, indicating limited community visibility and little external maintenance support.
Composer is used as the build tool, providing expected package tooling, but no security-scanning tooling is configured.
The repository has no security policy and no security-scanning tools. This weakens vulnerability reporting and maintenance transparency, although it is not by itself evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^1.10|^2.25 | — | — |
guzzlehttp/guzzle Version ^6.2|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.