The package includes a README, changelog, license, and release notes, and has no install-time scripts. The linked organization repository is correctly identified, but it lacks a security policy.
55%
Total Score
75
83
83
This is the only release, published about two and a half years ago, with no releases in the last 12 months. That leaves meaningful uncertainty about ongoing maintenance.
The repository recorded no commits and no active maintainers in the last three months, consistent with a project that may be inactive. No stronger maintenance evidence was provided to offset this.
The repository has zero stars, forks, and watchers, so there is little visible community support. Popularity is supporting evidence rather than a verdict, and the organization backing partly offsets this gap.
The repository has no published security policy, reducing transparency for reporting and handling vulnerabilities in an API client.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^6.4 || ^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.