The source includes tests, documentation, a matching license, and a GitHub release for this version. Long-term maintenance is uncertain, and the workflow uses unpinned action references, so pinning this exact release limits change risk.
58%
Total Score
75
90
75
This is the package's only release, published about two years ago, with no releases in the last 12 months. That makes ongoing maintenance uncertain despite the repository remaining available.
The repository recorded zero commits and zero active maintainers in the last three months. The lack of recent development is a meaningful abandonment concern for an SDK.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities. The package otherwise has a visible source repository and standard build tooling.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all 11 action references are unpinned. This is a supply-chain hygiene gap rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0 | — | — |
php-http/discovery Version ^1.12 | — | — |
php-http/client-common Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.