Its small dependency footprint and lack of install-time scripts reduce integration and supply-chain complexity. The MIT license, README, and release notes provide basic transparency, but there is no test suite or security scanning.
58%
Total Score
50
100
78
83
The repository is owned by an individual account rather than an organization, so there is no organizational backing signal to offset the thin maintenance evidence.
There has been only one release, published 782 days ago, with no releases in the last 12 months; this is a meaningful maintenance concern for a shipping API library.
There were zero commits and zero active maintainers in the last three months, consistent with the long gap since the only release and increasing abandonment risk.
The repository has zero stars, forks, and watchers, offering no supporting evidence of adoption or external review; this is secondary evidence rather than a standalone failure.
Composer is used for builds, but no security scanning tools were detected, leaving a modest repository hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
guzzlehttp/guzzle Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.