The repository has recent activity, tests, release notes, and organizational backing. Its single active contributor, three releases over roughly three and a half years, absent security policy, and unpinned workflow actions leave moderate maintenance and build-transparency concerns.
72%
Total Score
88
100
79
75
Only three releases have been published since March 2023, with a median interval of about 623 days, although one release arrived in the last 12 months. The long intervals indicate a small, infrequently released project.
One contributor made all 20 commits in the last three months, leaving no demonstrated contributor redundancy. Organizational backing partly compensates for this concentration, but the maintainer base remains narrow.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency gap, not a standalone severe concern.
The repository has no security policy, so the process for reporting and handling vulnerabilities is unclear.
Version 0.1.0 is not a stable major release, so the API may still change more readily than in a mature 1.x package; it is not marked prerelease.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
php-http/discovery Version ^1.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.