Clear documentation, tests, licensing, and a security policy make the release straightforward to evaluate and integrate. The organization backing and read-only workflow permissions provide useful safeguards, though the project has little history so far.
72%
Total Score
75
100
75
100
This is a very new package, 18 days old, with only one release and no established release interval; that limits evidence of sustained maintenance.
All recent commits come from one contributor, creating concentrated maintenance risk; organization ownership provides some capacity for handoff but does not demonstrate a second active contributor.
Two commits from one active maintainer in the last three months show some activity, but the limited volume provides only modest evidence of ongoing maintenance.
The repository has no stars, forks, or watchers. This is weak supporting evidence for maturity, but popularity alone is not decisive for a young SDK.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and defense-in-depth gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.