70%
Total Score
63
100
94
75
All commits in the last 3 months came from one contributor, creating a narrow recent contributor base. Organization backing reduces handoff risk, but it does not replace evidence of broader active contribution.
Only 1 commit was made in the last 3 months by 1 active maintainer. Recent releases compensate for some of this weakness, but the low commit activity leaves maintenance momentum uncertain.
The repository had 2 new issues and 2 merged pull requests in the last month, although no issues were closed and 11 remain open. This shows some responsiveness but also unresolved backlog.
The repository uses Composer, but no security-scanning tools were detected. Build tooling is present; the missing scanning is a modest transparency and maintenance gap.
The repository has no security policy. That is a real disclosure-process gap for a client library, though it does not by itself show abandonment or make the package unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/simple-cache Version >=1.0 | — | — |
php-http/discovery Version ^1.14 | — | — |
softcreatr/jsonpath Version ^0.10.0 || ^0.11.0 || ^1.0 | — | — |
psr/http-client-implementation Version ^1.0 | — | — |
psr/http-factory-implementation Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.