Clear documentation, tests, licensing, and recent repository work support adoption. The project is brand new and maintained by one contributor, while workflow references are unpinned and no security policy is published.
72%
Total Score
63
100
88
75
Only one registry account has publish access. That is consistent with the user-owned repository, but it leaves little publishing redundancy for a new package.
The repository is owned by an individual rather than an organization, so the concentrated contributor and maintainer base has no shown organizational handoff support.
This is a brand-new package with one release and no established release cadence, so long-term maintenance and compatibility remain unproven.
One contributor made 100% of the 18 recent commits, creating a meaningful continuity risk despite the current activity level.
Composer build tooling is present, but no security scanning tool was detected. For a package handling OAuth tokens, that is a modest transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
christianjbrown/api-client Version ^1.0 | — | — |
christianjbrown/key-value-store Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.