The project has one maintainer, no security policy, and little adoption evidence, which raises continuity concerns. MIT licensing, a clear README, stable versioning, and a matching repository provide useful transparency.
58%
Total Score
25
79
83
The package has 15 releases over nearly eight years, but its latest release was in August 2020 and there were no releases in the last 12 months. This is strong evidence of inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no current maintenance capacity.
Only one registry account has publishing access. That is a meaningful bus-factor concern for an individually owned project, although repository ownership matches the package.
The repository has 5 stars and 2 forks, providing little supporting evidence of broad review or community maintenance. Popularity is supporting evidence, so this is a modest concern rather than a verdict.
No security policy was found in the repository, leaving vulnerability-reporting expectations and response procedures unclear for a package that handles cloud API requests.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pimple/pimple Version ^3.0 | — | — |
monolog/monolog Version ~1.22 | — | — |
guzzlehttp/guzzle Version ~6.0 | — | — |
symfony/http-foundation Version ^4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.