Its clear README, MIT license, and simple dependency profile improve transparency. No security policy or repository security scanning leaves fewer safeguards around an already aging integration.
38%
Total Score
0
100
75
75
The package has had no releases in the last eight years, and all 10 releases were concentrated in February 2018. This strongly indicates abandonment, despite the package remaining available in the registry.
The repository recorded zero commits and zero active maintainers in the last three months, with its last push in February 2018. That leaves little evidence of ongoing maintenance capacity.
The repository has zero stars, one fork, and one watcher, providing little supporting evidence of community review or adoption. Popularity is only supporting evidence, so this does not determine the result alone.
Composer is used for the build, but no security scanning tools are configured. The missing scanning is a modest hygiene gap rather than evidence of an unsafe release by itself.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency and maintenance gap for an SDK handling API credentials.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.