This release appears healthy and suitable to depend on: it is actively released, non-prerelease, not deprecated, backed by an organization-owned repository, and shows recent repository activity from four contributors. The package and repository include substantial documentation, tests, changelog material, build tooling, and a matching package identity. The main reservations are missing security scanning and security policy documentation, plus broad top-level write permissions in both workflows; repository popularity is also currently negligible, although that is weak supporting evidence and is partly offset by the organization backing and active maintenance. Several other health dimensions were not collected, so confidence is below maximum.
88%
Total Score
100
100
89
80
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
firebase/php-jwt Version ^7.0 | — | — |
vlucas/phpdotenv Version ^5.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.