Release activity is thin, with only one release in the last 12 months, and recent repository work is absent; a single maintainer and no security scanning add some maintenance risk. The package is licensed, documented, tested in the repository, non-deprecated, and has no install-time scripts.
68%
Total Score
50
79
75
The package has 8 releases over 490 days but only 1 release in the last 12 months, indicating a sparse recent cadence despite a recent latest release.
The repository had 0 commits and 0 active maintainers in the last 3 months, which weakens evidence of ongoing maintenance even though the latest release was recent.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository-hygiene gap.
No security policy is published. This limits vulnerability-reporting transparency, though it is not by itself evidence of unsafe code.
Version 0.3.0 is not a stable major release, so consumers should expect more API change risk than with a mature 1.x package; it is not marked prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
brokeyourbike/http-enums Version ^2.0 | — | — |
brokeyourbike/http-client Version ^1.0 | — | — |
brokeyourbike/has-source-model Version ^3.0 | — | — |
brokeyourbike/data-transfer-object Version ^0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.