Documentation, tests, and release notes support integration. The license files conflict, and the repository has no security policy or scanning, leaving transparency and review gaps.
54%
Total Score
50
81
75
The manifest declares MIT, but the detected LICENSE file is Apache-2.0. Although a license is present, the mismatch should be resolved before relying on the release.
This is the package's only release, published 542 days ago, with no releases in the last 12 months; that creates a meaningful abandonment concern.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, providing no evidence of ongoing maintenance.
Composer build tooling is present, but no security scanning tools were detected; this is a modest review and maintenance gap.
The repository has no security policy, so there is no documented process for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twirp/twirp Version ^0.11 | — | — |
google/protobuf Version ^3.23 | — | — |
guzzlehttp/psr7 Version ^1.6.1|^2.0 | — | — |
firebase/php-jwt Version ^6.8 | — | — |
guzzlehttp/guzzle Version ^6.3|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.