The MIT license, README, tests in the repository, and clean dependency setup support straightforward adoption. GitHub Actions uses two unpinned references, and the repository has no security policy or security-scanning tool, so maintenance hygiene is not complete.
78%
Total Score
83
100
88
50
The repository is owned by an individual rather than an organization, so maintenance depends on a personal project rather than broader organizational backing.
The repository has only two stars and two forks, indicating a small user base; popularity is supporting evidence, so this modestly limits confidence rather than determining health.
Composer build tooling is present, but no security-scanning tool was detected, leaving security-maintenance coverage less mature.
The repository has no security policy, which reduces transparency about vulnerability reporting and handling.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7|^2.0 | — | — |
guzzlehttp/guzzle Version ^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.