The release has clear documentation, tests in the repository, licensing, and organization backing. Its maintenance record is too new to establish long-term reliability, and the workflow uses two unpinned actions.
70%
Total Score
75
100
88
75
This is the first release and the package is 0 days old, so there is no release history to demonstrate sustained maintenance; the repository is present and recently pushed, which partly offsets the concern.
There were no commits from active maintainers in the previous three months, but the package and repository are both newly created, so this currently shows limited history rather than established abandonment.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository hygiene gap.
The repository has no security policy, reducing transparency for reporting vulnerabilities in an SDK that handles API tokens.
The workflow was fully analyzed and uses read-only permissions with no detected dangerous sinks or audit findings, but both of its action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
php-http/discovery Version ^1.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.