Usable with caveats: the package is actively released, clearly backed by HelloAsso, and has a substantial documented SDK, but the repository shows no commits or active maintainers in the last three months and lacks security tooling and a security policy.
68%
Total Score
75
100
89
90
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful maintenance concern despite the same-day package release and recent push timestamp.
There are four open issues, with no issues or pull requests opened or closed in the last month; this suggests limited visible project interaction, though it is not evidence of abandonment by itself.
The repository has only 7 stars and 1 fork, which limits popularity-based reassurance, but low popularity alone does not make a small organization-backed SDK unsafe to use.
Composer build tooling is present, but no security scanning tools are reported, leaving a gap in repository-level security hygiene.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.