The package is newly published, so its maintenance record and long-term stability are not yet established. It includes tests, a substantial README, and a matching source repository, but has no security scanning and no observed commit history beyond its initial publication.
68%
Total Score
50
100
81
75
The repository is owned by an individual rather than an organization, so the project has a single-owner backing model and limited demonstrated institutional support.
This package is less than a day old with only two releases, so there is not enough release history to establish sustained maintenance. The rapid second release shows some immediate activity but does not offset the very limited record.
No commits or active maintainers were observed in the last three months. Because the package is newly published, this is mainly a coverage limitation, but it leaves sustained maintenance unproven.
Composer build tooling is present, but no security scanning tools were detected. That is a hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy, reducing transparency for reporting vulnerabilities in a package that handles API integration. This is a modest maturity gap for a new project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^6.4 || ^7.0 | — | — |
anthropic-ai/sdk Version >=0.54 <2.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
symfony/http-kernel Version ^6.4 || ^7.0 | — | — |
symfony/framework-bundle Version ^6.4 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.