The repository has had no commits for nearly eight months and offers no security policy. The package is clearly linked to its repository and declares MIT licensing, but its README says the project is still under construction.
44%
Total Score
0
71
75
Only two releases were published on the same day, with no newer release for nearly eight months. That limited history and long pause provide weak evidence of ongoing maintenance.
There were zero commits and zero active maintainers in the last three months, while the repository was last pushed nearly eight months ago. This is strong evidence that development has stalled.
The artifact includes a readable README, but it explicitly says the project is under construction and that not all features are implemented. Missing tests and a changelog are normal for a published package and are not counted against it.
Composer is used for the build, providing basic project tooling, but no security-scanning tool was detected. The missing scanner is a hygiene gap rather than proof that the release is unsafe.
The repository has no security policy. That reduces disclosure transparency for a package handling API clients, although it is not by itself evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^8.0 | — | — |
symfony/config Version ^8.0 | — | — |
psr/http-client Version ^1.0 | — | — |
symfony/serializer Version ^8.0 | — | — |
symfony/property-access Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.