Clear documentation, tests, release notes, and a matching MIT license support adoption. The workflow uses unpinned actions and the project has no security policy.
62%
Total Score
75
86
67
The package is less than a day old with only three releases, so it has little demonstrated history or long-term stability. The recent release activity is positive but cannot replace a track record.
One contributor made all 59 recent commits, leaving no demonstrated handoff capacity if that maintainer becomes unavailable. The active commit volume partly offsets the abandonment concern but does not remove the concentration risk.
Composer build tooling is present, but no security scanning tool was detected. For a package that handles API integrations, this is a modest transparency and maintenance gap.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a real but non-severe governance gap for a new client library.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, both action references are unpinned, so their contents can change without a repository change.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
christianjbrown/api-client Version ^1.0 | — | — |
symfony/dependency-injection Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.