The package includes a substantial README, tests, an Apache-2.0 declaration, and no install-time scripts. A security policy and organization ownership add useful support, though recent repository work is concentrated in one contributor.
82%
Total Score
67
100
94
100
One contributor made all 4 commits in the last 3 months. Organization ownership provides backing, but no second active contributor is shown to reduce short-term concentration risk.
Only 4 commits were made in the last 3 months, so recent source activity is modest despite the regular registry release cadence.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest repository hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
dallgoot/yaml Version ^1.0 | — | — |
aws/aws-sdk-php Version ^3.228 | — | — |
guzzlehttp/psr7 Version ^2.0 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
guzzlehttp/guzzle Version ^7.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.