Usable with caveats: it has a clear, licensed package, strong recent release history, and a matching organization-backed repository. However, the repository shows no commits or issue activity in the last three months and has no security policy or scanning, so verify ongoing maintenance before relying on it heavily.
68%
Total Score
50
100
88
90
The repository recorded zero commits and zero active maintainers during the last three months, despite a release history showing frequent publishing earlier. This is the strongest maintenance concern and raises the risk that development has stalled.
Only one registry account has publish access, which creates a narrow publishing base. The organization-backed repository provides some compensation, but the observed maintenance signals still make single-publisher concentration worth noting.
There were no new or closed issues or pull requests in the last month. With no reported backlog this is not severe, but it provides no evidence of active community support.
Composer build tooling is present, but no security scanning tools were detected. For an SDK handling API credentials and HTTP integrations, the missing security automation is a genuine hygiene gap.
The repository has no security policy. That weakens vulnerability-reporting transparency for a package used to connect applications to an external API.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amphp/amp Version ^3.1 | — | — |
nyholm/psr7 Version ^1.8 | — | — |
psr/container Version ^1.1 || ^2.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.