The declared MIT license, tests, changelog, README, and absence of install-time scripts support straightforward adoption. Six runtime dependencies and no repository security policy leave some safeguards unverified.
63%
Total Score
79
75
All five releases arrived within about three minutes on the first release day, and the package is now about five months old with no later release shown. That provides little evidence of an established maintenance cadence.
Composer is used for builds, but no security-scanning tool was detected in the repository. This is a modest transparency and maintenance gap rather than evidence of unsafe behavior.
The linked repository has no security policy. That makes vulnerability reporting and the project's response process less transparent, although it does not by itself show that the package is unsafe.
Version v0.1.4 is not a stable-major release, although it is not marked as a prerelease. The v0 status signals a still-maturing API and warrants care for production dependencies.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
jumbojett/openid-connect-php Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.