The MIT declaration and matching repository make the package easy to identify and inspect. Its minimal project structure and lack of security tooling provide little supporting evidence for dependable maintenance.
20%
Total Score
25
30
50
The published README explicitly says the SDK is under development and not to use it yet. The absence of tests and a changelog is not itself a packaging gap, but the README warning directly limits confidence in this release.
The package has had no release in about four years; all 17 releases were concentrated in the first eight days after publication, indicating the project was never maintained beyond its initial burst.
The repository recorded no commits and no active maintainers in the last three months, while its last push was in May 2022; this is strong evidence of abandonment.
Only one registry account has publishing access. That is not proof of weak maintenance by itself, but it leaves a thin visible maintainer base with no recent activity to offset the risk.
The repository has zero stars and forks and only one watcher. Popularity is not decisive, but these figures provide no compensating evidence for a very young, inactive project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/dotenv Version 6.0.* | — | — |
symfony/http-client Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.