The package has a clear MIT license, a usable README, and a small dependency surface. Its limited project history leaves less evidence of long-term maintenance or responsiveness. Pinning this version is reasonable only if the API meets your needs and you can accept limited ongoing support.
58%
Total Score
50
100
81
75
This is the only release, published about six months ago, so there is limited evidence of sustained release maintenance or a mature upgrade path.
There were zero commits and zero active maintainers in the past three months, while the repository's last push coincided with the initial release; this leaves maintenance responsiveness uncertain.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but this provides no community signal to offset the limited maintenance history.
Composer is used for the build, but no security scanning tools are present. This is a modest transparency and hygiene gap rather than evidence of unsafe behavior.
The repository has no security policy, making the process for reporting and handling vulnerabilities unclear for a package that handles trading API access.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.