The package includes tests, a useful README, release notes, and matching MIT licensing. Maintenance has stopped for about four years, with no recent commits, and the repository has no security policy or scanning tools.
58%
Total Score
67
81
83
The latest release was published about four years ago, with no releases in the last 12 months. This materially increases the risk of stale dependencies and limited maintenance.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the old latest release, this is strong evidence of inactive maintenance.
There are no new issues or merged pull requests in the last month, with one pull request still open. This is consistent with limited current maintenance, though the small issue backlog avoids a stronger concern.
Composer is used for the build, but no security scanning tools were detected. The missing scanning is a hygiene gap for a maintained library, while the build tooling itself is appropriate.
The linked repository is not archived, although its last push was about four years ago. The active repository status is reassuring, but the age of the last update reinforces the maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.5.6 || ^7.4.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.