Clear documentation, tests, and licensing make integration easier. The project has had no release in 406 days after only two releases, with no recent issue or pull-request activity; its security practices are also undocumented.
45%
Total Score
50
100
72
83
The package is 406 days old but has only two releases, both concentrated on its first day, and none in the last 12 months. This is strong evidence of limited ongoing maintenance for an SDK.
The repository is owned by an individual account rather than an organization. This is not inherently unhealthy, but it means there is no provided organizational backing to compensate for the thin maintenance record.
There are no open issues or pull requests and no issue or pull-request activity in the last month. Combined with the stalled release history, this supports an abandonment concern.
The repository has zero stars, forks, and watchers. This is only supporting evidence rather than a verdict, but it provides no external adoption signal to offset the maintenance gap.
Composer is used as the build tool, but no security scanning tools are present. For a small package this is a hygiene gap, though it is less significant than the inactive release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
illuminate/support Version ^8.0|^9.0|^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.