Clear documentation and a small dependency surface reduce adoption friction. Maintenance evidence is thin, so pinning this version is preferable until newer activity appears.
60%
Total Score
75
100
83
75
The package is about nine months old but has only two releases, both published within minutes, leaving little evidence of an established release cadence.
The repository recorded no commits and no active maintainers in the last three months, which weakens confidence that defects and compatibility issues will be addressed promptly.
The repository has one star, no forks, and no watchers, providing little community corroboration; the organization backing and matching package references partly offset this weakness.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy, so there is no documented channel or process for reporting vulnerabilities. This lowers maintenance transparency for an SDK handling API credentials.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.