The package is small, has a limited dependency surface, and includes tests and a readable package tree. Its last registry release was about 10 years ago, source activity stopped in July 2018, and the repository has little adoption or security oversight.
40%
Total Score
33
100
67
88
The latest release was about 10 years ago, with no releases in the last 12 months and only five releases overall. This is strong evidence of abandonment risk for a dependency.
There were no commits and no active maintainers in the last three months, while the last repository push was in July 2018. This indicates prolonged inactivity and raises abandonment risk.
One registry maintainer is consistent with a user-owned project, but it leaves little visible publishing redundancy. The concern is secondary to the observed inactivity.
The registry namespace and repository are owned by the same individual account, showing consistent ownership but no organizational backing. This offers limited maintenance capacity compared with an actively maintained team project.
The repository name matches the package name, supporting that it belongs to this package. However, the README does not mention the package name, leaving a minor transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ~6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.