This is a usable but relatively young package with a stable non-prerelease version, four releases over 90 days, a recent repository push, and organization backing from Aurigma. The main concerns are limited demonstrated maintenance depth—only three commits by one contributor in the last three months—along with no tests or changelog, no security policy, and no repository security scanning. These issues warrant caution for long-term dependency risk, but the unarchived repository, current release activity, license file, Composer tooling, and package-specific README provide meaningful compensating evidence.
72%
Total Score
80
100
78
90
The package has a substantial README, but it contains no packaged tests or changelog, and the repository also has neither. For an API client this weakens verification and change transparency, although the README documents installation, requirements, and usage.
The package is only 90 days old with four releases and a median interval of about 28 days, showing recurring publication but limited long-term history. This supports current activity while leaving maturity and durability less established.
One contributor made all three commits in the last three months, creating a concentrated bus factor. The organization-owned repository provides some handoff capacity, so this is a genuine resilience concern rather than a severe abandonment finding.
The repository had three commits in the last three months, all from one active maintainer. This demonstrates recent maintenance but indicates a thin activity level for a package with an active release stream.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this lowers external validation but does not by itself indicate that the package is unsafe to depend on.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
jumbojett/openid-connect-php Version ^0.9.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.