Usable with caveats: this is a well-documented, tested, correctly backed early release, but it has no demonstrated release or contributor history yet. Reassess after the project accumulates maintenance activity and security practices.
68%
Total Score
100
100
79
90
Version 0.1.0 was published on the same day as the package's first release, so there is no track record of sustained releases yet. This is an early-maturity concern rather than evidence of abandonment.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency and assurance gap for a new package, not a standalone adoption blocker.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. For a client that handles API credentials and remote requests, this is a genuine but limited maturity gap.
The package is on an unreleased major line at 0.1.0, which signals an API that may still change. It is not marked as a prerelease, so this is a moderate compatibility concern rather than a severe warning.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
composer/ca-bundle Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.