The package includes tests, a clear README, and release notes for this version. Its only release and zero commits in the last three months leave maintenance capacity unproven, while workflow pinning and permissions need tightening.
61%
Total Score
50
79
50
This package has existed for 185 days but has only one release, so there is little evidence of an established maintenance cadence.
The repository recorded zero commits and zero active maintainers in the last three months, leaving recent maintenance activity unproven despite the later push timestamp.
The repository uses Composer build tooling, but no security scanning tools were detected, leaving a modest transparency and review gap.
The repository has no security policy, which makes vulnerability reporting less clear for a package that handles Packagist credentials.
The release is v0.1.0 rather than a stable major version, which indicates an early-stage API and greater change risk for dependents.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-client Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.