A clear README, tests, MIT licensing, and an organization-backed repository improve adoption confidence. The main concern is no repository commits or active maintainers in the last three months, while no security scanning or policy leaves transparency weaker.
68%
Total Score
75
100
89
75
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Despite recent registry releases, this lack of observed source activity raises maintenance and abandonment concern.
The repository has 2 stars, 3 forks, and 1 watcher. This is limited community evidence, but popularity is only supporting evidence and the organization backing and release history partly compensate.
The repository uses Composer for builds, but no security-scanning tools were detected. The missing scanning coverage weakens development transparency without proving that the package is unsafe.
The repository has no security policy. For a cloud API SDK, this leaves vulnerability reporting and response expectations undocumented, creating a modest transparency gap.
No GitHub Actions workflows were analyzed, with 0 workflows total and no failed files. This provides no workflow risk evidence, but it also offers no evidence of automated build or release controls.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version * | — | — |
guzzlehttp/guzzle Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.