The artifact is small and focused, with tests, a README, and no install-time scripts. The repository could not be found, so ongoing maintenance and build provenance cannot be verified; its five-month history is still short.
63%
Total Score
50
50
90
100
Ten runtime dependencies create a relatively broad dependency surface for a small API client, adding maintenance and compatibility exposure without evidence here that the dependencies are problematic.
One registry account has publish access, but this administrative access list does not establish whether the project is actively maintained, so it does not offset the short release history.
The package has four releases across about five months, with releases roughly five days apart; this shows initial activity but provides limited evidence of sustained maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^2.0 || ^3.0 | — | — |
composer/semver Version ^3.2.5 | — | — |
guzzlehttp/psr7 Version ^2.0 | — | — |
vlucas/phpdotenv Version ^5.2 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.