Laravel adapter for the MAX Messenger Bot API client (geekcodev/max-php-client)
72%
Total Score
caution
Usable with caveats: active releases and tests are offset by a single-contributor maintenance base.
The repository is owned by an individual account rather than an organization, so the single-maintainer and concentrated-activity findings are not softened by visible organizational backing.
One contributor made 100% of the 21 recent commits, creating a genuine single-person continuity risk; the active release cadence partly offsets but does not remove it.
The repository recorded 21 commits in three months, but all activity came from one active maintainer, limiting continuity if that person stops work.
The repository has no published security policy. This is a transparency gap, although the presence of composer-audit provides some compensating security practice.
The workflow audit completed cleanly with no dangerous triggers, untrusted checkouts, injection findings, or high-severity issues. However, all three action references are unpinned, leaving workflow dependencies less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1|^2.0 | — | — |
guzzlehttp/guzzle Version ^7.15 | — | — |
laravel/framework Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.