Usable with caveats: this is a clean, stable, well-documented API client with tests and no deprecation or install-time scripts. However, it has only one release and no repository activity for about three months, with no security policy or scanning, so ongoing maintenance is uncertain.
62%
Total Score
75
100
83
90
The package is about three months old but has only one release, so there is little evidence of an established release process or sustained maintenance.
The repository recorded no commits and no active maintainers in the last three months, leaving little evidence that defects or API changes will be addressed promptly.
The repository has zero stars, forks, and watchers. This is weak supporting evidence rather than a decisive problem, especially for a small specialized client.
Composer is used as a build tool, but no security-scanning tooling is present. The missing scanning reduces maintenance transparency for a package handling API credentials and requests.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.