This release has strong packaging and repository hygiene: it is MIT-licensed, includes a README, tests, changelog, security policy, CI/security tooling, and no install-time lifecycle scripts or analyzed dangerous workflow patterns. The repository matches the package and is not archived, but the package was first released today with only one release, zero commits and zero active maintainers in the measured three-month window, and no popularity or issue-history evidence; these are primarily maturity and coverage limitations rather than proof of abandonment because the project is brand new. The single registry maintainer is consistent with a user-owned project, but ongoing maintenance capacity remains unproven, so adoption is reasonable with caution and monitoring for follow-up releases and activity.
68%
Total Score
50
100
83
90
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.