Tests, a clear MIT license, and no install-time scripts support routine use. The tiny repository footprint and lack of security process leave little independent assurance.
45%
Total Score
64
75
The package has 29 releases since August 2020, but none in the last 12 months and the latest release was about two years ago. This is a substantial maintenance and abandonment concern.
The linked repository name does not match the package name and its README does not mention the package. It may still be related, but ownership and source provenance are not clearly demonstrated.
Composer build tooling is present, but no security-scanning tools were detected. The build setup is ordinary, while the absence of scanning reduces assurance.
The repository has no documented security policy, leaving no clear process for reporting or handling vulnerabilities. This is a modest transparency gap for a package with no other security-process evidence.
The assessed version is 4.1.3, while the registry reports 3.4.0 as the latest version. That inconsistency weakens release transparency and confidence in the published version history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ekvio-dev/integration-php-sdk Version ^3 | — | — |
ekvio-dev/integration-app-contracts Version ^4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.