It has a clear MIT license, repository tests, and security scanning in its build. Organization backing and clean workflow auditing help, though no security policy is published.
67%
Total Score
67
86
83
This is a young package with one release over 59 days and no established release cadence. The limited history leaves maturity and long-term maintenance less demonstrated.
One contributor made all 13 commits in the last three months, creating a concentrated bus factor. Organization ownership provides some ability to hand maintenance off, but no second active contributor is shown.
The repository recorded 13 commits in the last three months, showing recent activity. However, the activity is concentrated in a single active maintainer, limiting evidence of broad maintenance capacity.
The repository has no published security policy. For an API connector handling authentication and financial-service integrations, this is a transparency gap.
Version 0.1.0 is an early non-stable-major release, so API and behavior stability are not yet well established. It is not marked as a prerelease, which provides a small compensating signal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.