It includes tests, a README, release notes, and a small dependency set, which support practical use. No security policy or scanning is present, and maintenance evidence is limited after the initial release.
58%
Total Score
100
81
75
The package has only one release, published over three years ago, with no releases in the last 12 months. That limits evidence of ongoing maintenance and compatibility work.
The repository has zero stars and forks and one watcher. This is only supporting evidence, but it indicates little visible community adoption or review.
Composer is used for builds, but no security-scanning tooling is configured. That weakens repository hygiene evidence, although it is not by itself a severe dependency risk.
The repository has no security policy, leaving the vulnerability-reporting process unclear. This is a transparency gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.0 | — | — |
alibabacloud/tea Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.