The package includes tests, a substantial README, Composer build tooling, and security scanning. Its small user footprint leaves little outside evidence of maturity.
58%
Total Score
50
100
88
83
A license file is present and detected as MIT, but the manifest declares Unlicense. The release is licensed, yet the mismatch creates avoidable legal and transparency uncertainty.
The repository recorded zero commits and zero active maintainers in the last three months. For a package only about four and a half months old, that is a meaningful warning about ongoing maintenance.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This does not prove abandonment, but it offers no evidence of community support.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but the absence of any visible community footprint provides little external reassurance.
The repository has no security policy. That is a transparency gap for an SDK handling API credentials and webhook verification, although security scanning provides some compensation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.