The package is clearly early-stage, with only 24 of 165 API endpoints covered. MIT licensing, repository tests, release notes, and Dependabot provide useful support, but workflow controls need tightening.
55%
Total Score
50
86
50
The package and repository are maintained under a single user account rather than an organization. That is consistent with a small personal project but leaves a thinner apparent continuity and bus-factor cushion.
The package has had no registry releases in the last 12 months, and its five releases were concentrated around November 2024. This indicates a meaningful maintenance gap for a package still described as early development.
The repository recorded zero commits and zero active maintainers during the last three months. For an early-stage client with incomplete API coverage, that weakens confidence in ongoing maintenance.
No security policy is present in the repository. This is a transparency gap for a client that handles authenticated API credentials, although it does not by itself indicate abandonment.
The assessed version is 0.1.3, while the registry reports 0.1.2 as the latest version and the package is still below 1.0. This creates release-state uncertainty and signals an immature API.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0.3 | — | — |
psr/http-message Version ^2.0.0 | — | — |
php-http/discovery Version ^1.19.2 | — | — |
psr/http-client-implementation Version * | — | — |
psr/http-factory-implementation Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.