The package has a clear MIT license, tests, and a matching organization-owned repository. Its release history is short and repository activity has been idle since the second release, while no security scanning is shown.
62%
Total Score
75
86
50
Only two releases exist over about 10 months, with both released within the first week; this provides limited evidence of an established maintenance cadence.
The repository recorded no commits and no active maintainers in the last three months, limiting evidence of ongoing maintenance after the initial release period.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
The repository has no published security policy, reducing transparency for reporting and handling vulnerabilities in an SDK that makes API requests.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.2 | — | — |
beberlei/assert Version ^2.9 | — | — |
psr/http-message Version ^1.0 | — | — |
kriswallsmith/buzz Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.