It is licensed, has a small dependency footprint, and includes usable setup documentation. The limited project safeguards mean your team would need to own compatibility and maintenance.
38%
Total Score
50
100
71
75
The latest release was published in December 2017, with no releases in the last 12 months. This long period without releases is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, providing no evidence of current maintenance.
Only one registry account has publishing access, and the project is owned by a user rather than an organization. Combined with the inactive repository, this suggests a thin maintenance base.
The repository has three stars and one fork, indicating limited adoption and external validation. Popularity is supporting evidence only, so this modestly reinforces other concerns rather than deciding the result.
Composer is used for the build, but no security scanning tools are present. This is a hygiene gap that adds some maintenance concern without independently making the release unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.