This release appears generally suitable to depend on: it is a stable MIT-licensed package with a substantial generated client tree, tests, no install-time lifecycle scripts, no registry deprecation, and a strong recent release cadence of 14 releases over the last 12 months. The linked repository is active, organization-owned, and not archived, which helps offset its low popularity and single-contributor concentration. The main concerns are that all three recent commits came from one contributor, the repository has no security scanning or security policy, and it lacks a changelog; these reduce transparency and resilience but do not by themselves indicate abandonment or make the release unfit.
78%
Total Score
80
100
89
90
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.