The linked project was updated in January 2025 and includes tests, release notes, and a clear Apache-2.0 license. One workflow uses an unpinned action, and no security policy is published.
42%
Total Score
75
57
67
Packagist marks the entire package as abandoned and names azuracast/php-api-client as its replacement. This is a direct adoption concern even though the replacement project is active.
The latest registry release was 2022-01-24, with no releases in the last 12 months. The long release gap materially raises the risk of depending on this package rather than its replacement.
The repository recorded zero commits and zero active maintainers in the last 3 months, despite a more recent push being visible in repository status. This indicates no current development activity in the measured period.
The linked repository does not match the package name and its README does not mention this package, although the project backing identifies AzuraCast as the organization owner. The mismatch warrants caution about package-to-repository identity.
The repository uses Composer build tooling, but no security scanning tools were detected. The established build tooling is positive, while the missing scanning capability is a modest hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.