The MIT license, matching repository, tests, and substantial README support adoption. Maintenance evidence is weaker, with no recent registry releases and no commits in the last three months; security safeguards are also limited.
68%
Total Score
50
88
50
The package has made no registry releases in the last 12 months, and its latest release was about 14 months ago. This is a meaningful maintenance concern despite nine releases overall.
There were no commits and no active maintainers in the last three months. The recent repository push is a compensating sign of availability, but it does not demonstrate ongoing development.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
The linked repository has no published security policy, leaving vulnerability reporting and response expectations unclear for a package that handles API credentials.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version 2.7.1 | — | — |
symfony/process Version v7.3.0 | — | — |
guzzlehttp/guzzle Version 7.9.3 | — | — |
symfony/http-client Version v7.3.1 | — | — |
wikimedia/composer-merge-plugin Version ^2.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.