The SDK is clearly documented and has a clean, licensed artifact with repository tests. Organization ownership and recent releases help offset the young project, but the small active contributor base and workflow hygiene leave more operational risk than a mature dependency.
68%
Total Score
67
100
88
67
The package is young at 107 days, with three releases and a median interval of about 42 days. This shows active early development but not yet a long maintenance record.
All three recent commits came from one contributor, so maintenance depends heavily on a single person. Organization ownership provides some handoff capacity but does not remove the concentration risk.
There were three commits in the last three months, showing some recent activity, but the volume is modest for a young SDK.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a modest transparency and maintenance gap, not evidence of compromise.
The repository has no security policy. For an SDK handling bearer API credentials, this weakens vulnerability-reporting transparency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.