Usable with caveats: it is a small, clearly licensed package with documentation and a matching source repository, but maintenance evidence is thin. All three releases arrived within hours on the first day, followed by 107 days without commits, and the project has one publisher with no tests or security tooling.
58%
Total Score
38
100
72
90
The repository recorded zero commits and zero active maintainers over the last three months, despite being only 107 days old. This is the strongest indication that maintenance may have stopped after the initial release burst.
A single registry publisher limits publishing redundancy and creates a narrow operational base, although the linked repository identifies the same individual owner.
The repository is owned by an individual account rather than an organization, so the single-publisher structure is less readily compensated by institutional backing.
The package is only 107 days old and all three releases were concentrated within hours on its first day, so there is little evidence of sustained release maintenance.
There are no open issues or pull requests and no activity in the last month; this is not inherently bad for a small package, but it offers no evidence of an active user or maintenance community.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.