B2B Soft REST API integration library
64%
Total Score
caution
No recent commits, no README, and a repository/package naming mismatch limit confidence.
Only one registry publishing account is listed, which creates limited publishing redundancy. The repository owner is also a personal account, so there is no organization backing shown to compensate for that narrow base.
The package includes tests and the repository has tests, which supports basic project maturity. The missing README and changelog reduce consumer documentation, though the absent changelog is not itself a packaging defect.
The registry namespace and repository owner are both Arkitecht, but the owner is a personal account rather than an organization, providing limited visible institutional backing.
There were zero commits and zero active maintainers in the last three months, a meaningful maintenance concern, although the same-day repository push and release history provide some compensating evidence.
The repository name does not match the package name and the package name was not found in the README; because this signal does not establish a clear package-to-repository match, it lowers transparency confidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^3 | — | — |
guzzlehttp/guzzle Version ^7.1 | — | — |
netresearch/jsonmapper Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.