The repository has no commits from active maintainers in the last three months, despite a recent push and three releases in the last year. Its small footprint and lack of security scanning add limited assurance.
66%
Total Score
75
50
89
83
Six runtime dependencies, including the PHP runtime, Composer installer, API client, and Symfony components, create a meaningful but not excessive dependency surface.
There were zero commits and zero active maintainers in the last three months, a meaningful maintenance warning even though the repository has a recent push and the registry shows recent releases.
The repository has only 2 stars and no forks or watchers. Popularity is supporting evidence rather than a verdict, but this provides little external adoption evidence.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and assurance gap.
The repository has no security policy, which makes vulnerability reporting and response expectations less clear for a package that integrates with an external provider.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/serializer Version ^5.2 | — | — |
symfony/property-access Version ^5.2 | — | — |
blesta/composer-installer Version ~1.0 | — | — |
openprovider/rest-client-php Version v2.0.2-beta@dev | — | — |
phpdocumentor/reflection-docblock Version ^5.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.