This is a usable and currently maintained release with a stable major version, eight releases over the last 186 days, a recent repository push, a non-archived source repository, clear MIT licensing, and no install-time lifecycle scripts. The main concerns are that all 12 commits in the last 3 months came from one contributor, the repository has no tests or security scanning, and it has very little adoption evidence; organization ownership provides some maintenance continuity but does not eliminate the single-contributor risk. Overall, it appears reasonable to adopt with normal dependency review and monitoring, but it is not as resilient or transparent as a mature, broadly maintained package.
72%
Total Score
70
50
88
88
The package has four runtime dependencies, a moderate and understandable dependency surface for an HTTP and Azure authentication library; no development dependencies are present, consistent with the absence of repository tests but offering less evidence of a maintained test setup.
Only one registry account has publishing access. This is a concentration risk, although the linked repository is owned by an organization, which provides some compensating project backing.
A substantial README and changelog are present, and GitHub Releases are used, but neither the artifact nor the repository contains tests. For a low-level authentication and middleware library, the absence of repository tests is a meaningful maintenance and regression risk.
One contributor made 100% of the 12 commits in the last 3 months, creating a real continuity risk. Organization ownership partly compensates because maintenance can potentially be handed off, but no second active contributor is evidenced.
There were no new or closed issues or pull requests in the last month, so the signal shows no active issue resolution. Because issue counts are partly unknown and recent commits exist, this is a limited caution rather than a severe concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.8 || ^8.0 | — | — |
azure-oss/identity Version ^1.0 | — | — |
caseyamcl/guzzle_retry_middleware Version ^2.13 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.