The package is clearly licensed, documented, and has a focused dependency set with a repository that matches its name. Its lack of tests and security scanning adds maintenance uncertainty. Pin this version only if the stable API integration is still actively verified in your project.
58%
Total Score
67
100
81
50
Only one registry publishing account is listed, indicating a thin publishing base. The linked repository is user-owned rather than organization-owned, so there is no provided evidence of broader backing.
The package includes a substantial README and changelog; the absence of packaged tests is normal for a published library artifact, while repository tests are also absent. Documentation compensates for the missing test coverage only partly, so the overall signal remains a caution.
There has been only one release, published over three years ago, with no releases in the last 12 months. This is substantial evidence of low maintenance activity.
The repository had no commits and no active maintainers during the last three months, consistent with a project that has been dormant since its initial release.
Composer build tooling is present, but no security scanning tools were detected. For a small API integration this is a meaningful hygiene gap, though not evidence of abandonment by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.