This release appears suitable to depend on from a maintenance and transparency perspective: it is a stable v1.1.0 package with a substantial README, tests, changelog, license file, reproducible-looking Composer scaffolding, and an actively updated, non-archived organization-owned repository. Recent activity includes 24 commits from two equally active maintainers, which is a reasonable base factor for a young project. The main reservations are the package's short 146-day history, very low repository adoption, absent security scanning and security policy, and incomplete GitHub Actions permission declarations, including a release workflow with write permissions. These concerns warrant review of the CI and release setup, but do not by themselves make the package unfit to adopt.
82%
Total Score
100
100
83
80
The package has six releases over 146 days, showing active development, but the short overall history means long-term maintenance is not yet established.
The repository has only 1 star, no forks, and no watchers, providing little external adoption evidence; this is a caution about maturity and community validation, not a standalone reason to reject the package.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-process gap that should be reviewed before high-risk use.
The repository has no SECURITY.md or other detected security policy, which weakens vulnerability-reporting and response transparency.
One CI workflow lacks top-level permissions and the release workflow declares write permissions. Although this is not inherently unsafe, the incomplete least-privilege posture warrants review of the workflow jobs and release-token scope.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-message Version ^1.1|^2.0 | — | — |
php-http/discovery Version ^1.20 | — | — |
psr/http-client-implementation Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.