The MIT license, included tests, and small dependency set make the package straightforward to inspect and integrate. Its maintenance and security practices are too stale for a dependable new dependency, with no recent activity or security policy.
38%
Total Score
25
100
72
50
The package has only 2 releases, both from November 2017, and none in the last 12 months; the latest release is nearly nine years old. This is strong evidence of abandonment, though the package is not marked deprecated.
The repository recorded 0 commits and 0 active maintainers in the last three months, consistent with the nearly nine-year-old last push. This is the clearest abandonment risk in the assessment.
The registry lists one maintainer, and the project backing identifies a user-owned repository rather than an organization. A narrow maintainer base offers little visible resilience if that person is unavailable.
The repository has 0 stars, 1 fork, and 1 watcher, indicating little observable adoption or community support. Popularity is supporting evidence rather than a verdict, but it provides no compensating maintenance signal here.
Composer is used for the build, which fits the ecosystem, but no security scanning tools were detected. This is a modest transparency and maintenance-process gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
carono/rest-client Version @stable | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.