The small single-maintainer project has no tests, changelog, README, or security policy, which limits transparency and supportability. Its Composer setup is straightforward, the repository is not archived, and the package is not deprecated.
58%
Total Score
50
100
83
75
One registry maintainer is consistent with an individually owned project, but it provides little publishing redundancy when release activity has already stopped.
The artifact and repository contain no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the absent README reduces consumer guidance for this SDK.
The package has had six releases, but all were concentrated around its May 2025 launch and none appeared in the last 12 months; this is meaningful abandonment risk for a library dependency.
The repository has no security policy. That weakens vulnerability-reporting transparency, although it is a moderate hygiene gap rather than a severe dependency risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.