Usable with caveats: this is a well-documented initial release with tests, release notes, and matching organization-backed source code. It has no demonstrated maintenance history yet, and the repository lacks security scanning and a security policy.
68%
Total Score
75
100
83
88
This is the first release, published 0 days ago, so there is not yet evidence of a sustained release cadence. That is an early-maturity concern rather than abandonment evidence for a package released today.
There were zero commits and zero active maintainers in the preceding 3 months, but the repository was created and pushed very recently. This leaves maintenance capacity unproven rather than demonstrating a collapsed project.
Composer build tooling is present, but no security-scanning tools were detected. For an SDK handling API credentials and HTTP requests, the missing scanning coverage is a real maintenance and transparency gap.
The repository has no security policy. That makes vulnerability reporting and response expectations less transparent for a dependency intended to handle API communication.
Version v0.1.0 is an initial non-stable-major release, which signals that the API may still change. It is not marked as a prerelease, providing some indication that the publisher considers it usable.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
php-http/discovery Version ^1.18 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.