Organization backing, clear documentation, repository tests, and licensing support long-term adoption. The missing security policy and workflow hygiene are minor concerns, while the older release line merits checking compatibility with current project needs.
68%
Total Score
67
94
83
The package has 67 releases since January 2019, but none in the last 12 months and the latest registry release was in December 2022. This is a meaningful maintenance concern despite the historically frequent release cadence.
There were no commits and no active maintainers in the last three months. The recent repository push is compensating evidence, but the lack of recent commit activity still weakens confidence in ongoing maintenance.
The repository has four open issues and three open pull requests, but no new or closed issues or pull requests in the last month. This suggests limited recent interaction, though the backlog is small.
No security policy was found in the repository. This is a transparency gap for a client library that handles cloud credentials and API requests.
The single workflow has no untrusted-trigger sink and no top-level write permissions, but all three action references are unpinned and it installs a package outside a lockfile. These are low-level reproducibility and build-hygiene concerns, not severe risks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3|^7.0 | — | — |
mtdowling/jmespath.php Version ^2.5 | — | — |
adbario/php-dot-notation Version ^2.4.1 | — | — |
clagiordano/weblibs-configmanager Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.