The proprietary license may restrict redistribution, and the repository has no security policy or security scanning. The generated client is well documented and has no install-time scripts, but its legacy status limits confidence in future support.
42%
Total Score
0
100
75
75
The package has had only two releases, both in January 2023, with no releases in about three years and eight months. That sustained lack of releases is a meaningful abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the package's long period without releases. No provided maintenance signal compensates for that inactivity.
The manifest declares a proprietary license, so the release is licensed but may impose restrictions that make it unsuitable for some projects. No license file was detected to clarify those terms.
The repository has no security policy and no security scanning tools were detected. This is a transparency and maintenance gap, though it does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.