The package is clearly identified, MIT-licensed, and documents the release with a README and release notes. Its small community and lack of a security policy reduce confidence in long-term support.
56%
Total Score
33
100
81
83
There were zero commits and zero active maintainers in the last three months. Combined with the February 2024 last push and no recent registry releases, this indicates a substantial abandonment risk.
The repository is owned by a user account rather than an organization, so there is no provided evidence of organizational maintenance backing. This makes the already thin activity record more consequential, but does not establish abandonment by itself.
Only two releases were published, with the latest on December 19, 2023 and none in the last 12 months. This is a meaningful sign of limited ongoing maintenance for a package whose integration depends on an external service.
There were no new or closed issues or pull requests in the last month, and no open issues or pull requests. This is consistent with a small, quiet project but provides little evidence of active support.
The repository has 7 stars, 1 fork, and 1 watcher, indicating a very small user and contributor community. Popularity is only supporting evidence, but this leaves limited external validation and resilience if the sole owner stops maintaining it.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.