Tests, a clear Apache-2.0 license, and a small dependency footprint provide useful basics. The package should not be adopted for new projects without an actively maintained replacement.
8%
Total Score
0
100
42
75
Packagist marks the entire package as abandoned, with no replacement specified. This directly indicates that maintainers do not support continued dependency use.
The package has had no releases in the last 12 months, and its latest release was about three and a half years ago. The four releases were concentrated within a very short initial period, showing no ongoing maintenance.
There were zero commits and zero active maintainers in the last three months, consistent with the archived repository and long release gap. This leaves no observed maintenance capacity.
The linked repository is archived, and its last push was about three and a half years ago. Archived source is a severe abandonment risk for a dependency.
Composer build tooling is present, but no security-scanning tools were detected. This is a secondary hygiene gap rather than the main adoption risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.