This release appears suitable to depend on: it is stable, licensed, non-deprecated, backed by an organization-owned repository, has a substantial README and test suite, and was released and pushed very recently. The main concerns are modest release frequency, very low repository popularity, complete concentration of recent commits in one contributor, and the absence of a repository security policy or security-scanning tooling. These are meaningful resilience and transparency gaps, but they are partly offset by current maintenance activity, organization backing, integration tests, and clean package structure without install-time scripts.
78%
Total Score
90
100
83
90
The package has existed for 1,188 days and has two releases in the last 12 months, including the assessed release, but only four releases overall and a median interval of about 261 days indicate a relatively deliberate release cadence.
All three recent commits came from one contributor, giving a complete short-term commit concentration and creating continuity risk. Organization ownership provides some capacity to hand off maintenance, so this is caution rather than a severe failure.
The repository has only 1 star, 0 forks, and 1 watcher. Low popularity is supporting caution about external adoption and review, but it is not by itself evidence of abandonment for a specialized client library.
Composer build tooling is present, but no security-scanning tools were detected. The build setup is appropriate, while the missing scanning capability is a modest transparency and defense-in-depth gap.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a genuine transparency gap for a library that handles remote API authentication and data operations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0.0|^3.0.0 | — | — |
psr/http-client Version ^1.0.0 | — | — |
psr/http-factory Version ^1.0.0 | — | — |
psr/http-message Version >=1.0 | — | — |
composer/ca-bundle Version ^1.3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.