It has a clear README, repository tests, an MIT license, and no install-time scripts. The source repository matches the package and is active, but the available evidence does not yet demonstrate long-term maintenance or security processes.
64%
Total Score
50
81
75
The package is only 5 days old, despite 4 releases in that period; this shows active initial work but provides little evidence of sustained maintenance.
One contributor made all 3 commits in the last 3 months, leaving maintenance dependent on a single person with no demonstrated handoff capacity.
Composer build tooling is present, but no security-scanning tools were detected; this is a modest process gap rather than evidence of unsafe code.
The repository has no security policy, which reduces transparency for reporting and handling security issues in a package that verifies webhook signatures.
Version v0.3.0 is not a stable major release, so its API and behavior may still change as the project matures.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
php-http/discovery Version ^1.19 | — | — |
psr/http-client-implementation Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.