The source is a tiny ten-file library with no tests, README, or license, and the repository has no security scanning. It is not deprecated or archived, but its maintenance evidence is too old for a dependable current dependency.
40%
Total Score
0
61
83
The latest release was published about eight years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk, despite the package having six historical releases.
The repository recorded zero commits and zero active maintainers in the last three months, and its last push was about eight years ago. No provided signal shows current maintenance capacity.
The package has no declared license, detected license, or license file. That creates a real adoption and redistribution concern with no repository licensing evidence to compensate.
The artifact has no README or tests, while the repository also has neither; the missing tests weaken confidence in a library, and the missing README makes integration less transparent. The GitHub release flag is a small positive for release traceability.
The repository name does not match the package name, and no README mention was collected. That creates some uncertainty that the linked repository is the package's intended source.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
unapi/unapi Version ^1.1.2 | — | — |
guzzlehttp/guzzle Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.