The package includes a clear README, tests, an MIT license, and a small, directly relevant dependency set. It lacks a security policy and automated workflow coverage, leaving maintenance and security practices less visible.
65%
Total Score
75
100
88
83
This is a young package at 168 days old with only one release, so there is limited evidence of sustained maintenance or release maturity.
There were zero commits and zero active maintainers in the last three months, which materially limits evidence that the package is being maintained after its initial release.
Composer build tooling is present, but no security scanning tools were detected, leaving security hygiene less visible for a package handling API credentials.
The repository has no security policy, reducing transparency about how vulnerabilities and credential-related issues should be reported.
No workflows were present to audit, so there are no detected workflow hazards, but this also provides no evidence of automated checks or secure release automation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0|^13.0 | — | — |
ethelserth/biblionet-php Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.