The stable 1.0.2 release, organization-backed repository, and single runtime dependency provide a reasonable foundation. The 12-character README, absent tests, and missing security policy leave limited evidence for maintenance and safe integration.
62%
Total Score
50
100
78
75
The repository recorded zero commits and zero active maintainers in the last three months, which is the clearest evidence of uncertain ongoing maintenance.
A README is present, but it contains only 12 characters; absent tests and a changelog are normal for a published artifact and are not counted as gaps here.
The package is 444 days old with only two releases and one release in the last 12 months, indicating a sparse release cadence but not clear abandonment because version 1.0.2 was published recently.
The repository has zero stars and forks and one watcher. This provides little community validation, although popularity alone is not decisive for a small package.
Composer is used as a build tool, but no security scanning tools are configured. The build tooling is appropriate, while the missing scanning is a modest transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.9.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.