The package has a very small source tree and no security policy, limiting evidence of mature maintenance. Its MIT declaration and lack of install scripts reduce adoption friction.
32%
Total Score
25
71
75
This is the only release, published nearly eight years ago, with no releases in the last 12 months. That strongly indicates abandonment risk for a dependency.
The repository has recorded zero commits and zero active maintainers in the last three months, consistent with the nearly eight-year release gap. No provided maintenance signal compensates for this inactivity.
Only one registry maintainer is listed, leaving little visible publishing capacity. The linked repository is user-owned rather than organization-backed, so there is no provided evidence of a broader maintainer base.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counts provide no additional maturity signal.
Composer is used for builds, which is appropriate, but no security-scanning tooling is present. This is a modest transparency and hygiene gap, not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.