The project has recent releases, clear documentation, tests, a changelog, and a matching source repository. Its main limitation is that recent work comes from one contributor, with no published security policy or automated security scanning.
78%
Total Score
83
93
75
All three recent commits came from one contributor, giving the project a single-person maintenance dependency. The repository is user-owned rather than organization-backed, so there is no shown handoff capacity to offset that concentration.
Composer build tooling is present, but no security scanning tools were detected. This is a transparency and maintenance gap, though it is not by itself evidence that the release is unsafe.
The repository has no security policy, leaving no documented channel or process for reporting vulnerabilities. This lowers project transparency but is not a severe dependency risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/simple-cache Version ^3.0 | — | — |
guzzlehttp/guzzle Version ^7.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.