The package is explicitly alpha, and no security scanning or security policy is configured. A README and changelog are present, while the repository matches the package and is not archived.
38%
Total Score
0
100
69
75
Only three releases were published, all around July 2025, with no release in the last 12 months despite the package being over a year old. This indicates a substantial maintenance gap.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the absence of recent release activity and raising abandonment risk.
A license file is present, but the artifact declares MIT while the detected license is GPL-3.0. This mismatch creates material uncertainty about the terms governing use.
Composer build tooling is present, but no security-scanning tools are configured. The project therefore provides limited automated evidence of ongoing dependency or code-health checks.
The linked repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This is a transparency and maintenance weakness for an API client library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
saloonphp/saloon Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.