The package has a clear README, a substantial test suite, an MIT declaration, and no install-time scripts. Its small dependency surface and matching repository make integration straightforward.
64%
Total Score
75
100
81
83
The package has seven releases over roughly six years, including one release in the past year. This shows continued publishing, but the low recent cadence limits confidence in active maintenance.
There were zero commits and zero active maintainers in the past three months. The recent registry release partly offsets this, but the repository currently provides weak evidence of ongoing development.
Composer is used for the build, which fits the package ecosystem, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap.
The repository has no security policy. That does not make the package unsafe by itself, but it leaves vulnerability reporting and response expectations undocumented.
Version 0.2.0 is not a prerelease, but it remains below a stable major version. That suggests the API may still change for consumers.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.