Healthy and suitable to depend on, with a small maintainer-risk caveat. It has active recent releases, a clear README, tests in the repository, and no deprecation or workflow red flags, but all recent commits come from one contributor and the project lacks a security policy.
78%
Total Score
75
100
94
75
The registry namespace and repository owner match, but the owner is an individual user rather than an organization; this supports package identity while offering limited evidence of institutional maintenance capacity.
All 16 commits in the last three months came from one contributor, leaving a meaningful continuity risk if that person becomes unavailable. The repository is user-owned rather than organization-owned, so there is no shown organizational handoff benefit.
Composer build tooling is present, but no security-scanning tools were detected. This is a transparency gap, though the clean workflow findings and active repository partly compensate for it.
No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented for a security-sensitive API client.
The CI workflow does not declare top-level token permissions. No write permissions were detected, but explicitly restricting permissions would provide stronger workflow transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1|^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.