52%
Total Score
caution
Usable with caveats: maintenance has gone quiet after a short beta-only release history.
Tests and a changelog are present in the repository, which supports basic project maturity, but the README still contains placeholder text and an unfinished usage example. The documentation gap lowers adoption confidence.
The package has only 3 releases, all within about 10 days, and no release activity after November 27, 2025 despite being about 10 months old at collection. This is a meaningful maintenance concern.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Combined with the short release history, this points to limited recent maintenance capacity.
Composer build tooling is present, but no security-scanning tools were detected. This is a hygiene gap rather than evidence that the package is unsafe.
No repository security policy was found. That reduces transparency for reporting and handling issues, although the README does provide an email contact for security reports.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1|^2.0|^3.0 | — | — |
guzzlehttp/guzzle Version ^6.2|^7.10 | — | — |
league/oauth2-client Version ^2.8 | — | — |
mtdowling/jmespath.php Version ^2.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.