Usable with caveats: the release is clearly structured, licensed, tested, and backed by a matching repository, but it is brand new with almost no maintenance history and no security policy or scanning. Adopt it only if you can accept the limited track record.
68%
Total Score
50
100
88
90
The registry namespace and repository owner are consistent, but the owner is an individual account rather than an organization, so the project has a relatively narrow visible backing base.
Only two releases exist, with the latest published about 26 minutes after the first, so there is not enough history to demonstrate sustained maintenance.
The repository has zero commits and zero active maintainers during the last three months, indicating no demonstrated maintenance history. The recent push is consistent with the package being newly created, but does not establish long-term support.
Composer build tooling is present, but no security scanning tools were detected, leaving a meaningful security-hygiene gap for an SDK that handles authentication and private keys.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations for a package that communicates with an external notification API.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.8|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.