The small, focused codebase has tests, a changelog, clear licensing, and organization backing. Its last registry release was in 2017 and there has been no commit activity in the past three months, so maintenance should be treated as limited.
58%
Total Score
75
79
50
The package has only three releases, with the latest on July 5, 2017 and none in the last 12 months. This is substantial evidence of stale maintenance for a dependency intended to track a cloud service.
There were zero commits and zero active maintainers in the past three months. Combined with the old release history, this is a meaningful maintenance and abandonment concern.
The repository uses Composer, which is appropriate for a PHP package, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than evidence that the release is unsafe.
No repository security policy was found. That reduces transparency for reporting and handling security issues, though it is less serious for this small, focused SDK than evidence of abandonment.
Version 0.2.1 is not a prerelease, but it remains below a stable 1.0 major release. That modestly limits maturity confidence, while the absence of prereleases is a compensating positive.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.