Healthy and usable for most projects, with strong early maintenance and clear release documentation. The main caveats are that the package is only 43 days old, has no security policy or security scanning, and its GitHub Actions workflow does not declare top-level permissions.
78%
Total Score
80
100
78
80
Only one account has registry publish access, but this administrative fact is partly offset by two active repository contributors. It leaves limited publishing redundancy without showing abandonment.
The package is young at 43 days, but it has already had five releases in the last 12 months, including the assessed release within the first nine days. This shows active early iteration, though long-term maintenance is not yet established.
There is one open issue and no issues or pull requests were opened or closed in the last month. For a repository only 43 days old, this is limited evidence rather than a strong abandonment signal.
The repository has zero stars and forks and only one watcher. This offers little external validation, but popularity alone is supporting evidence and does not outweigh the active code history.
Composer build tooling is present, but no security scanning tool was detected. The missing scanning lowers supply-chain transparency, though it is not by itself evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
saloonphp/saloon Version ^4.0 | — | — |
league/oauth2-client Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.