This release appears healthy and reasonable to depend on: it has a stable non-prerelease version, regular release activity over more than three years, a repository that is active and not archived, substantial documentation and tests, CI/build tooling, security scanning, and no registry deprecation or install-time scripts. The main concern is maintenance concentration: all 25 commits in the last three months came from one contributor, while the repository has no security policy and its workflows do not declare top-level token permissions. These are meaningful transparency and continuity gaps, but they do not outweigh the strong evidence of recent maintenance and package completeness.
86%
Total Score
80
100
100
80
The repository is owned by a user account rather than an organization, so the single active contributor in the recent activity represents a genuine bus-factor concern rather than an organization-backed handoff model.
All 25 commits in the last three months were made by one contributor, giving the project a concentrated maintenance base and increasing continuity risk if that contributor becomes unavailable.
The repository has no security policy, which weakens vulnerability-reporting and disclosure transparency for a package that communicates with a remote API.
Both workflows lack top-level GitHub Actions permissions declarations. Although no top-level write permissions were observed, explicitly restricting workflow token permissions would provide stronger supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1|^2.0|^3.0 | — | — |
symfony/mime Version ^6.4|^7.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
fp4php/functional Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.