The repository is tiny, has no tests, and provides no security policy or scanning. It does have a README, a matching source repository, and no install scripts, which limits integration and packaging concerns.
55%
Total Score
50
100
75
67
Only one registry publishing account is listed, leaving limited visible publishing redundancy. Because the repository is user-owned rather than organization-backed, this is a meaningful resilience concern.
The package has had no releases in the last 12 months, and its latest release was about 18 months ago. Four releases over its lifetime show some initial activity but do not offset the current gap.
There were no commits and no active maintainers in the last three months. This is direct evidence of currently inactive development for a young, pre-1.0 package.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of any visible adoption provides no community backstop for this small project.
Composer is used for the build, but no security scanning tools are configured. The missing scanning reduces maintenance transparency without showing an immediate dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.