The matching repository, clear README, and organization ownership make the small client straightforward to inspect. Its only release is about 14 months old, with no recent commits, and it has no license or security policy, so future maintenance and usage rights are uncertain.
58%
Total Score
67
100
78
88
There were no commits and no active maintainers in the last three months, and the repository was last pushed about 14 months ago. This is the strongest evidence that maintenance may have stalled.
No declared license, license file, or detected repository license is present. This creates a real transparency and usage-rights concern for a package intended to be depended on.
This package has only one release, published about 14 months ago, with no releases in the last 12 months. That limited history and lack of recent delivery reduce confidence in ongoing maintenance.
The repository has zero stars, forks, and watchers, providing no supporting evidence of broad community adoption. The organization backing and small package scope partly offset this, so it is not a severe risk alone.
Composer is used as the build tool, which fits the package ecosystem. No security scanning tools are configured, leaving a modest repository hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
guzzlehttp/guzzle Version ^7.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.