The Apache-2.0 license, matching repository, and clear README make the package transparent to consume. Organization backing and a stable version help, but its maintenance record is too new to establish ongoing support.
68%
Total Score
75
100
88
75
The package is only 0 days old with two releases published within minutes, so there is not enough observed history to judge sustained maintenance.
The repository reports zero commits and zero active maintainers over the last 3 months; given the package's age this is not evidence of abandonment, but it leaves maintenance capacity unproven.
The repository uses Composer for its build, which fits the package ecosystem, but no security-scanning tool was detected. For this tiny type-definition package that is a minor hygiene gap.
The repository has no security policy. This reduces transparency for reporting issues, although the package is a small metapackage with no runtime code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/guzzlehttp-guzzle-impl Version ~8.2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.