Usable with caveats: it is a licensed, non-deprecated package with documentation, tests, and a matching source repository. However, it has had no release in about two years and no repository commits in the last three months, so ongoing maintenance is uncertain.
62%
Total Score
75
100
83
88
Only two releases were published, both around two years ago, with no releases in the last 12 months. This is a meaningful sign of limited ongoing maintenance for a library integration.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old latest release, this indicates uncertain current maintenance.
The repository has no stars, forks, or watchers, providing no supporting evidence of a broader user or contributor base. Popularity is only supporting evidence, so this is a caution rather than a severe risk.
Composer is used as a build tool, but no security scanning tools are reported. This is a modest transparency gap, while the absence of build complexity is reassuring.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This matters for an SDK handling API credentials, though it is not by itself evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.