The codebase has no automated tests or security scanning, and its single-maintainer setup offers limited resilience. MIT licensing, a matching repository, and no install scripts reduce adoption friction.
55%
Total Score
50
80
75
One registry maintainer is responsible for publishing the package, leaving little visible publishing redundancy. The linked repository is also owned by an individual account, so no organizational backing offsets this concern.
All six releases arrived within roughly 13 hours, and there has been no release activity during the remaining 135-day package lifetime; this suggests an unproven maintenance cadence.
The repository recorded zero commits and zero active maintainers in the last three months. The package is young, which partly limits the abandonment signal, but there is no recent development evidence.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe dependency risk.
The linked repository has no security policy. For a client library handling API credentials, the absence reduces transparency around vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
php-http/discovery Version ^1.20 | — | — |
php-http/client-common Version ^2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.