The package has no tests or repository security scanning, while its 14 runtime dependencies add maintenance burden. A README, MIT license declaration, and matching non-archived repository provide useful transparency.
42%
Total Score
0
50
75
50
The latest release was about 7 years ago, with no releases in the last 12 months. Fourteen historical releases show prior activity, but the long current gap strongly raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the release gap. This indicates the project is not receiving visible maintenance.
The package declares 14 runtime dependencies, including several framework and HTTP components. This increases maintenance exposure for a project with no recent visible activity.
Composer build tooling is present, but no security scanning tools were detected. That leaves dependency and source-risk checks less visible, though it does not by itself show an unsafe build.
The linked repository has no security policy. For an SDK handling authentication and access tokens, this is a meaningful transparency and vulnerability-reporting gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pimple/pimple Version ^3.0 | — | — |
symfony/cache Version ^3.3|^4.0 | — | — |
monolog/monolog Version ^1.22 | — | — |
illuminate/cache Version ^5.6 | — | — |
illuminate/queue Version ^5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.