Risky to adopt: the package has had no release or repository activity for about nine years and remains at an early 0.x version. It has a clear license, tests, documentation, and matching organization-backed source repository, but those strengths do not offset the abandonment risk.
38%
Total Score
50
100
63
83
Only two releases were published, with the latest on January 31, 2017 and none in the last 12 months; roughly nine years without a release is a strong sign of abandonment for a library dependency.
There were zero commits and zero active maintainers in the last three months, consistent with the roughly nine-year release gap and increasing abandonment risk.
The repository has zero stars and forks and only one watcher, providing little evidence of an active user or contributor community; popularity is supporting evidence rather than decisive on its own.
Composer is used as the build tool, which fits the PHP package, but no security scanning tools are configured; the absent scanning is a minor hygiene gap.
The repository is not archived, which is a positive counterpoint, but its last push was on January 31, 2017, so the non-archived status does not demonstrate current maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.