This release appears usable and generally well maintained: it is a stable 2.3.0 release from a package with nearly three years of history, 19 releases, five releases in the last 12 months, a matching and actively pushed repository, tests, clear licensing, and no install-time scripts or deprecation status. The main adoption risks are concentrated maintenance capacity—only one active contributor and one commit in the last three months—and limited security transparency, with no security policy or security-scanning tools reported. The absence of a changelog and GitHub Actions is a smaller hygiene concern rather than evidence of abandonment, but the package should be monitored for maintainer continuity and upstream Apple API changes.
72%
Total Score
60
50
94
90
Eight runtime dependencies, including cryptographic, HTTP, and certificate-related libraries, create meaningful transitive maintenance exposure; the profile is not excessive for an App Store server API client but warrants dependency monitoring.
Only one registry account has publish access. This is a genuine publishing continuity risk for a user-owned project, although repository activity provides some compensating evidence.
The repository owner is an individual user rather than an organization, so there is no organizational maintenance redundancy to offset the concentrated contributor base.
All recent commits came from one contributor, giving the project a single-person bus factor and increasing continuity risk.
Only one commit was recorded in the last three months from one active maintainer, showing that maintenance has slowed or is highly concentrated.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hoels/ocsp-php Version ^0.1 | — | — |
firebase/php-jwt Version ^7.0 | — | — |
guzzlehttp/guzzle Version ^7.8 | — | — |
phpseclib/phpseclib Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.