The project has tests, a changelog, a clear license, and recent maintenance activity. Its small contributor base and missing security policy leave less evidence for long-term support.
68%
Total Score
50
100
81
75
Only one registry account has publish access. That is a real publishing single point of failure for this user-owned project, although repository activity shows the same maintainer is still active.
The repository is owned by a user rather than an organization, so the single-maintainer and single-contributor concentration is not offset by visible organizational backing.
The package has existed for about 8 years with 12 releases, but only one release in the last 12 months and a median interval of about 195 days indicate a deliberate, relatively slow cadence.
All two recent commits came from one contributor, so maintenance depends entirely on that person and has no demonstrated handoff capacity.
Two commits from one active maintainer in the last three months show ongoing work, but the low volume provides only limited evidence of sustained maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lcobucci/jwt Version ^4.0 | — | — |
guzzlehttp/psr7 Version ^2.1.4 || ^3.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
psr/simple-cache Version ^1.0 | — | — |
guzzlehttp/guzzle Version ^6.3 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.