The MIT license and matching source make provenance clear. Its minimal four-file artifact and absence of security scanning leave limited evidence for ongoing care.
42%
Total Score
0
58
50
There were no commits and no active maintainers in the last three months. Combined with the old last-pushed date, this is strong evidence of abandonment rather than a brief lull.
The repository is not archived, but it was last pushed in December 2019—nearly seven years ago—despite the later registry release. That strongly suggests the source is no longer actively maintained.
The package has had three releases but none in the last 12 months, and version 0.0.3 is the latest after roughly 18 months of registry history. This points to stalled maintenance.
Composer is used for builds, but no security scanning tool is present. This is a modest transparency and maintenance gap, not a severe risk by itself.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. For a small SDK this is a minor but real maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
rmccue/requests Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.