The repository includes tests, a substantial README, and a clear MIT license. Its tiny community, narrow individual ownership, and lack of security policy reduce confidence for a security-sensitive client.
58%
Total Score
50
83
75
The repository is owned by an individual rather than an organization, so the package has less visible institutional backing to compensate for its single-release and inactive-maintenance profile.
This is the package's only release, published over a year ago, with no releases in the last 12 months. That leaves limited evidence of sustained maintenance for a security-sensitive library.
There were no commits or active maintainers in the last three months, consistent with the package's single-release history. This materially increases the risk that defects or protocol changes will go unaddressed.
The repository has only 2 stars, 1 fork, and no watchers. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of external review or adoption.
Composer build tooling is present, but no security scanning tools were detected. For a library handling certificate and account operations, that is a meaningful hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
spatie/dns Version ^2.5 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-message Version ^1.0|^2.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.