Clear documentation, tests, and release notes make integration easier. Organization backing helps, but absent security scanning and a missing security policy leave important maintenance gaps.
68%
Total Score
88
100
89
80
No commits and no active maintainers were recorded during the past three months. This is a meaningful maintenance-capacity concern, even though the registry shows recent releases and the repository was recently pushed.
The repository has zero stars, forks, and watchers, providing no community adoption evidence; popularity is supporting evidence, so this is only a modest concern.
Composer build tooling is present, but no security scanning tool was detected. The missing scanning reduces transparency around dependency and build hygiene.
The repository has no security policy, leaving maintainers' vulnerability-reporting and response process unclear.
The only workflow does not declare top-level token permissions. Although no write permissions were observed, explicit least-privilege settings would provide stronger workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
php-http/discovery Version ^1.0 | — | — |
psr/http-client-implementation Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.