The repository has no security policy or security-scanning tooling, reducing transparency for a broad AI integration library. The MIT license, substantial README, repository tests, and lack of install scripts provide useful safeguards, but the project still appears immature and inactive.
45%
Total Score
33
100
83
75
There were zero commits and zero active maintainers in the last three months, a meaningful sign that maintenance may have stopped after the initial release burst.
The repository is owned by a user account rather than an organization, providing no visible organizational backing to offset the thin maintenance record.
The package is only 103 days old with three releases, all published in a short burst; the limited history gives little evidence of sustained maintenance.
There were no issues or pull requests opened or closed in the last month; with no other recent activity, this does not demonstrate an active maintenance process.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these values provide no external signs of adoption or review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.1 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.