This is a usable but relatively young package with a stable non-prerelease version, a live organization-owned repository, recent publication activity, and a clear license file. The main concerns are limited maturity evidence: only three releases over 90 days, just two commits in the last three months by one contributor, no tests or changelog, no security policy or scanning tools, and negligible repository adoption. The generated-client structure and organization backing partly compensate for the documentation and contributor-base gaps, but the package should be adopted with ordinary dependency pinning and maintenance monitoring rather than treated as a mature, broadly validated dependency.
68%
Total Score
80
100
78
90
A 2,464-character README documents installation, prerequisites, and usage, but the artifact and repository have neither tests nor a changelog. For an API client this is a genuine maintenance and transparency gap, though the usage documentation is useful compensation.
The package is only 90 days old with three releases and a median release interval of about 45 days. This demonstrates ongoing publishing but provides limited evidence of long-term maintenance maturity.
All two recent commits came from one contributor, creating a concentrated bus factor. Organization ownership provides some handoff capacity, but no second active contributor is evidenced.
Only two commits were made in the last three months by one active maintainer. Recent activity exists, but the low volume limits confidence in sustained maintenance.
The repository has zero stars, forks, and watchers, so there is no external adoption evidence to support maturity. Popularity is only supporting evidence, but this still warrants some caution for a young package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
jumbojett/openid-connect-php Version ^0.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.