Usable with caveats: the package is clearly tied to its repository, has a README, stable versioning, and no deprecation or install-time scripts. It is very young, all recent commits come from one contributor, and the proprietary license and missing security policy reduce transparency for a production API client.
61%
Total Score
67
100
79
83
The manifest declares a proprietary license and no license file was found, which limits the transparency and redistribution expectations of this dependency.
The package is only 97 days old and published all seven releases within roughly six days; no later release is shown, so long-term maintenance is not yet demonstrated.
One contributor made all five recent commits, leaving no demonstrated maintainer redundancy if that contributor becomes unavailable.
Five commits were made in the last three months, showing some activity, but the volume is modest for a young API client.
Composer is used as a build tool, but no security-scanning tooling is present, leaving repository-level security hygiene less transparent.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.