The package has strong documentation, tests, release notes, and a clear Apache-2.0 license. Ongoing repository activity is limited to one commit from one contributor in three months, while the organization backing reduces—but does not remove—the concentration risk.
78%
Total Score
67
100
89
75
One contributor made all commits in the last three months, creating a concentrated maintenance path. Organization ownership provides some handoff capacity, so this is a caution rather than a severe risk.
Only one commit was recorded in the last three months, from one active maintainer. The recent release history shows the project is not abandoned, but current development activity is thin.
The repository has 0 stars, 5 forks, and 1 watcher. This is weak supporting evidence, but popularity is not decisive for a small organization-backed connector.
Composer build tooling is present, but no security scanning tools were detected. The strong tests and CI evidence partly offset this transparency gap.
The repository has no security policy, leaving vulnerability-reporting expectations unclear for consumers of an API connector.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
guzzlehttp/psr7 Version ^2.12.3 | — | — |
guzzlehttp/guzzle Version ^7.15.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.