The package has clear licensing, a usable README, and a stable release. Its last release and repository activity were over three years ago, while the repository has no tests or security policy and uses two unpinned workflow actions.
50%
Total Score
50
100
83
67
Only two releases were published, both on the same day in May 2023, with no releases in the last 12 months. This indicates a largely inactive package and lowers confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the release history showing no activity for over three years. No newer maintenance evidence compensates for this.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these values provide no additional adoption or maintenance signal.
The repository has no security policy. That is a transparency and vulnerability-reporting gap, especially for an API integration package, though it is not severe on its own.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, both of its two action references are unpinned, leaving a modest reproducibility and workflow supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.5.0 | — | — |
laravel/framework Version ^9.0 | — | — |
mautic/api-library Version ^3.1.0 | — | — |
graham-campbell/manager Version ^4.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.