Clear documentation, licensing, and a matching organization-backed repository make the package transparent. Its short history, single active contributor, no tests, and absent security policy leave maintenance risk for production use.
67%
Total Score
67
86
83
The package is only 26 days old and has one release, so there is little evidence of sustained maintenance or release maturity.
One contributor made all two recent commits, concentrating maintenance in a single person; organization backing provides some ability to hand work off but does not remove the observed concentration.
There were two commits in the last three months, showing some activity but only a very small maintenance history.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Version v0.1.0 is an early, non-stable-major release, which indicates the API may still change.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version 6.*|7.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.