The source remains available and clearly identifies the package, with a valid MIT license and usable README. Organization backing helps, but the lack of security tooling leaves less evidence for safe long-term maintenance.
45%
Total Score
75
64
50
Packagist marks the entire package as abandoned, with no replacement specified beyond the same package name. This is a substantial warning for continued support and dependency safety.
The package has 32 releases but none in the last 12 months; the latest release was published over four years ago. That strongly suggests the published dependency is no longer receiving regular updates.
No commits or active maintainers were recorded in the last three months. Although the repository is not archived, this provides little evidence of current maintenance capacity.
Composer and Robo provide build tooling, but no security scanning tools were detected. That is a maintenance and transparency gap, though not severe on its own.
The repository has no published security policy. For an SDK handling API credentials and encrypted data, this reduces transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.