This is a coherent, minimally scoped PHP client with an MIT license, a matching organization-backed repository, tests in both the artifact and repository, a clear README, no install-time lifecycle scripts, and no declared runtime libraries beyond PHP extensions. However, v1.0.0 was released only minutes before assessment, with just one release and no historical release or maintenance record; the repository also shows no commits in the preceding three months, no security policy, and no security scanning. The package is therefore usable but lacks the maturity and operational evidence expected for a dependable long-term dependency.
62%
Total Score
83
100
83
90
This is the first and only release, published on the assessment date, so there is no observed history of maintenance, compatibility evolution, or release stability.
No commits or active maintainers were observed in the preceding three months. Although the repository was pushed on the assessment date, the absence of any established activity history is a meaningful maintenance concern.
Composer build tooling is present, but no security scanning tools are configured, leaving a security-hygiene gap for future changes.
The repository has no security policy. For a client handling API credentials and webhook signatures, this reduces transparency about vulnerability reporting and response expectations.
The assessed version is a stable v1.0.0 rather than a prerelease, but the stable label is supported by no prior release history because the package is brand new.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.