The package includes a clear README, tests, an MIT license, and no install-time scripts. Its project has no security policy or recorded issue activity, so maintenance maturity remains unproven.
62%
Total Score
50
75
50
The package name and README match the linked repository, while the repository is owned by an individual account rather than an organization; this gives limited backing evidence without indicating a mismatch.
Only one release has been published over 59 days, so there is not enough history to establish a dependable maintenance cadence.
The repository has no issues or pull requests and no activity in the last month; for a new project this is limited evidence, but it does not prove abandonment.
The repository has zero stars, forks, and watchers, providing no supporting evidence of community adoption; popularity is only secondary evidence.
Composer build tooling is present, but no security-scanning tool is reported, leaving a modest verification gap for a security-focused SDK.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.1 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.