Clear licensing, tests, README, and release notes make the small package easy to inspect. Its organization backing and matching repository add confidence, but check whether its older Guzzle dependencies fit your project.
65%
Total Score
75
100
88
83
The package has six releases over roughly six years, but none in the last two years and four months. That points to limited ongoing maintenance for a dependency, though the latest release is documented.
There were no commits and no active maintainers in the last three months, consistent with the longer release pause and indicating little recent maintenance capacity.
There are no open issues or pull requests, which is compatible with a small focused package, but there is also no recent issue or pull-request activity to demonstrate active maintenance.
Composer build tooling is present, but no security-scanning tool was detected. For this small package that is a hygiene limitation rather than a severe dependency risk.
The repository has no security policy. This reduces transparency around vulnerability reporting, although the package is small and the absence alone does not show an active security problem.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0|~7.0 | — | — |
guzzlehttp/promises Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.