The package has a small, lightly active repository with no security policy or licensing evidence. Its release notes and usable README add some transparency, but do not offset the limited maintenance record.
45%
Total Score
50
50
67
88
There has been only one release, published over two years ago, with no releases in the last 12 months. This is strong evidence of limited ongoing maintenance for a dependency.
The package declares ten runtime dependencies, including HTTP, caching, Symfony, and XML components. This is a meaningful dependency surface to maintain, though the dependencies are relevant to the SDK's apparent functionality.
No declared license, license file, or repository license file was detected. That creates a real transparency and usage-risk concern for a package intended to be integrated into applications.
Only one registry account has publishing access. Because this is a user-owned project, the narrow publisher base provides little redundancy when combined with the absence of recent releases.
The repository name does not match the package name and its README does not mention the package. Although a name mismatch can be normal for a sub-package, the absence of any README reference creates uncertainty that this repository is the package's intended home.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.5 | — | — |
symfony/mime Version ^5.4|^6.0 | — | — |
symfony/cache Version ^5.0 | — | — |
psr/simple-cache Version ^1.0 | — | — |
nyholm/psr7-server Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.