Healthy and suitable to use, with strong release activity, clear documentation, tests, and an active organization-backed repository. The main concern is that all recent commits come from one contributor and the CI workflow does not declare token permissions.
82%
Total Score
90
100
89
90
One contributor made all 13 commits in the last 3 months, creating a real continuity risk. Organization ownership partly compensates because maintenance can potentially be handed off internally.
The repository has zero stars, forks, and watchers, so there is little public adoption evidence; however, low popularity is not decisive for a young, actively released SDK.
Composer build tooling is present, but no security-scanning tool is configured, leaving a modest transparency and assurance gap.
The only workflow lacks top-level token permissions. No write permissions were observed, but explicitly limiting permissions would provide stronger CI hardening.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.