The package includes tests, a README, a changelog, and a clear MIT declaration, but its maintenance signals are weak. Pinning this release leaves you dependent on an archived, deprecated project with no registry releases or repository commits in roughly eight years.
15%
Total Score
0
100
50
75
Packagist marks the entire package as abandoned, with no replacement listed. This is a severe adoption warning because the package is no longer presented as maintained.
The last registry release was on October 20, 2017, with zero releases in the last 12 months. Roughly eight years without a release is strong evidence of abandonment for a library targeting an external API.
The repository has recorded zero commits and zero active maintainers in the last three months. This confirms there is no current maintenance activity to offset the old release history.
The linked repository is archived, even though it was pushed in June 2024. Archiving indicates the project is no longer intended for normal active development and outweighs its otherwise useful source history.
The repository has no security policy. This reduces transparency for reporting vulnerabilities, although it is secondary to the stronger abandonment signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.