Healthy and reasonable to depend on. It has a long release history, a current non-archived organization-backed repository, tests, release notes, and recent commits from two contributors; the main caveat is that its GitHub workflows do not declare top-level token permissions and the repository has no security scanning tools.
82%
Total Score
100
100
89
83
The repository has only five stars and two forks, indicating a small user base. Popularity is limited but does not outweigh the evidence of active maintenance and organization backing.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and automated-risk-control gap.
Both workflows lack top-level token permission declarations, leaving their default GitHub Actions token permissions less explicit than recommended. No workflow declares top-level write access, which limits the severity of this gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.0|^7.0 | — | — |
markrogoyski/math-php Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.