The package includes a clear README, repository tests, and no install-time scripts. Its lack of activity and security policy, combined with the package-level deprecation, makes this release a poor dependency choice.
18%
Total Score
0
50
75
Packagist marks the entire package as abandoned, with no meaningful replacement identified; this is a severe warning for continued dependency use.
The package has only three releases and none in the last three years, indicating a long period without registry maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with abandonment rather than active maintenance.
A license file is present and the release declares MIT, but the detected file text is MIT-0, so the declaration and artifact license do not match exactly.
The repository is not archived, which preserves a possible maintenance path, but it was last pushed in July 2023 and does not offset the prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.4 | — | — |
laravel/framework Version ^9.0|^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.