The source repository includes tests and a changelog, has a matching package name, and uses Dependabot. Its workflows leave all six actions unpinned and provide no security policy, adding maintenance and build-hygiene concerns.
43%
Total Score
50
100
75
67
This is the package's only release, published 540 days ago, with no releases in the last 12 months. That strongly increases abandonment and compatibility risk for a library dependency.
The package and repository are owned by the same individual account, and the project is not presented as organization-backed. This offers less visible institutional continuity, although ownership is consistent.
There were no new or merged pull requests and no issue activity in the last month, while the repository has no open pull requests. Together with the single release, this suggests very limited current maintenance.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but this provides no community signal to offset the package's limited release history.
The repository has no security policy. For an API client, this is a transparency gap, though it is less severe than evidence of unsafe release or workflow behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0.3 | — | — |
psr/http-message Version ^1.1.0|^2.0.0 | — | — |
php-http/discovery Version ^1.20.0 | — | — |
psr/http-client-implementation Version ^1.0.1 | — | — |
psr/http-factory-implementation Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.