The project includes tests, a changelog, a clear README, and an MIT license. It lacks a security policy and automated security scanning, so pin this version and plan an upgrade path.
58%
Total Score
50
100
86
75
The package has 15 releases over more than 12 years, but none in the last 12 months and its latest registry release was in March 2021. That long release gap is a meaningful maintenance concern.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the absence of recent releases. The repository is not archived, but current maintenance capacity is unclear.
There were no new or closed issues or pull requests in the last month, with two open issues and one open pull request. This reinforces the picture of an inactive project.
Composer is used for the build, but no security scanning tools were detected. The established build tooling helps reproducibility, while the missing scanning reduces maintenance assurance.
The linked repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency and maintenance gap for a library that depends on external rate services.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version 5.* || 6.* || 7.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.