Tests and a small dependency set help, but the project has not released or been pushed since August 2018. The package also lacks licensing and consumer documentation, so pinning it carries substantial maintenance and legal risk.
34%
Total Score
75
100
56
83
Only two releases exist, both in August 2018, with no release in more than eight years and none in the last 12 months. This is strong evidence of abandonment for a library dependency.
The package declares no license and contains no license file; the linked repository also has none. That leaves developers without clear permission to use or redistribute the code.
Tests are present in both the package and repository, which provides some quality evidence. However, the package has no README and no changelog, limiting consumer guidance and release transparency.
There are no open issues or pull requests and no recent issue or pull-request activity. Combined with the old release and push dates, this provides no evidence of ongoing maintenance.
The repository name does not match the package name, and no README mention was found. This creates some uncertainty that the linked repository is the package's intended source, despite the related naming context.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.