The source matches the package, includes a license, and avoids install-time scripts. The single maintainer and absent security policy provide limited evidence of ongoing support.
58%
Total Score
50
92
75
One registry maintainer is a thin support base for a user-owned project. The matching repository ownership provides accountability but does not demonstrate ongoing capacity.
There has been only one release, published about 3 years ago, with no releases in the last 12 months. That is a meaningful maintenance concern for a dependency, though the stable 1.0.0 version may be complete.
The repository recorded no commits and had no active maintainers in the last 3 months, consistent with the last push being about 3 years ago. This is the strongest evidence of possible abandonment.
The repository has no security policy, reducing transparency about vulnerability reporting and response. This matters more when maintenance activity is already absent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.8 | — | — |
guzzlehttp/promises Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.