This release appears usable and actively backed by an organization: it is not deprecated or archived, has a recent repository push, uses stable releases, includes a README and license file, and has no install-time lifecycle scripts or risky workflows. However, the package is relatively young at 90 days with only four releases, repository activity is light at three commits in the last three months and concentrated in one contributor, and there are no tests, changelog, security policy, or security-scanning tools. The generated-client structure and organizational ownership provide some context for the hygiene gaps, but the thin activity and single-contributor bus factor warrant caution before adopting it for a critical dependency.
70%
Total Score
70
50
78
90
Seven runtime dependencies, including standard PHP extensions, Guzzle components, and an OpenID Connect client, represent a moderate dependency surface for an API client. The profile is not excessive, but each runtime dependency adds maintenance exposure.
A substantial README is present, but neither the artifact nor repository contains tests or a changelog. The documentation is useful for this API client, yet the missing validation and release-history documentation remain hygiene gaps.
The package is young at 90 days and has only four releases, with a median interval of about 28 days. This shows ongoing publication but provides limited evidence of long-term maturity.
All three recent commits came from one contributor, giving a complete concentration of activity in a single person. Organization ownership partly mitigates handoff risk, but no second active contributor is evidenced.
Only three commits were made in the last three months by one active maintainer. Recent activity exists, but it is light and offers limited evidence of sustained maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
jumbojett/openid-connect-php Version ^0.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.