It includes tests, a stable release, and an MIT license, which make the small library easier to evaluate. The workflow uses four unpinned actions, and the repository lacks a security policy and clear package-name mention.
47%
Total Score
100
63
75
The package has had only three releases, all concentrated in November 2022, with no release in roughly 3 years and 10 months. This is strong evidence of stalled maintenance, although the repository is not archived.
The package includes tests and the repository also has tests, providing some validation coverage. The missing README and changelog are transparency gaps for a library, though the tests partly compensate for maintainability concerns.
The repository name does not exactly match the package name, and no README package mention was available. This weakens package-to-repository traceability, although the shared organization and commons-style repository name make a monorepo or subpackage relationship plausible.
The repository has zero stars and forks, with only three watchers. Popularity is supporting evidence rather than a verdict, but these values provide little evidence of broad community support.
Composer and Make are used for project tooling, but no security-scanning tools are reported. The missing scanning is a hygiene gap, not evidence of unsafe code by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.