The package is clearly licensed and has a small dependency surface. Its single release was over five years ago, with no recent activity, tests, security policy, or meaningful adoption evidence.
40%
Total Score
50
100
61
67
Only one release exists, published over five years ago, with no releases in the last 12 months. This strongly suggests abandonment risk despite the stable 1.0.0 version.
The repository is not archived, but it was last pushed over five years ago. The lack of recent repository activity reinforces the maintenance concern from the release history.
The artifact is a small, focused PHP library containing source files and Composer metadata. Its narrow scope is not itself a concern, but the tree shows no tests or consumer documentation.
The release includes GitHub release notes for version 1.0.0, documenting the initial release. It has no README, tests, or changelog, limiting consumer guidance and project transparency.
The repository is owned by an individual account rather than an organization, so there is no visible organizational backing to compensate for the thin maintenance record.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.