The MIT license and package-to-repository match make its provenance clear. Its small footprint, absent security policy and tooling, and negligible popularity add little confidence for long-term support.
35%
Total Score
0
33
50
The package has had only two releases, both in February 2018, with no release in about 8 years and 7 months. That strongly indicates abandonment risk for a library integrating with external APIs.
The repository recorded no commits and no active maintainers in the last 3 months, while its last push was in February 2018. This confirms that the long release gap reflects inactive development rather than a stable maintenance cadence.
The repository has 1 star and 2 forks, providing little external evidence of broad review or community support. Low popularity alone is not decisive, but it offers no compensation for the inactive maintenance record.
Composer is used for the build, but no security scanning tools are configured. This is a modest supply-chain hygiene gap, though it is less significant than the prolonged inactivity.
The repository has no security policy. For an API wrapper that handles authentication tokens, this reduces transparency and makes vulnerability reporting less clear.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.