Usable with caveats: it is actively releasing and backed by an organization, but it is a very young pre-1.0 SDK with only one recent contributor and no security policy. Depend on it cautiously until its maintenance base and project controls mature.
68%
Total Score
67
100
86
75
All recorded recent commits come from one contributor, giving the project a single-person bus factor. Organization ownership provides some handoff potential, but no second active contributor is shown.
Only one commit from one active maintainer was recorded in the last 3 months. Recent package releases show activity, but repository development capacity is currently thin.
Composer is used for builds, but no security-scanning tool was detected. The absence of scanning is a meaningful control gap for an SDK handling API credentials and regulated-data claims.
The repository has no security policy. That reduces transparency about vulnerability reporting and response expectations for a package intended for production API integrations.
Version v0.7.4 is not a stable major release, so the API may still change materially. It is not marked as a prerelease, which partly offsets that concern but does not remove the pre-1.0 risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^2.0 | — | — |
php-http/discovery Version ^1.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.