Usable with caveats: this is a newly published, actively generated client with a clear license and repository-backed tests, but it has only one day of history and limited security-maintenance evidence. Reassess after it demonstrates sustained maintenance.
68%
Total Score
75
100
75
67
The package is only 1 day old with 4 releases, and the 0.25-day median interval reflects initial publication rather than an established maintenance record. Its recent release activity is positive, but there is not yet enough history to demonstrate durability.
There are no recorded commits or active maintainers in the last 3 months, but the repository is only 1 day old and was just updated. This is insufficient history for a strong maintenance verdict rather than evidence of abandonment.
The repository has zero stars, forks, and watchers. For a package published only 1 day ago this is unsurprising, but it provides no independent adoption evidence.
Composer build tooling is present, but no security-scanning tools were detected. The build setup supports reproducibility, while the missing scanning is a modest transparency gap.
The repository has no security policy. For a client handling OAuth2 credentials and webhook signatures, this weakens the documented process for reporting and responding to vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.