The package is documented, tested, licensed, and avoids install-time scripts. Its very recent launch leaves maintenance capacity and long-term stability unproven, while no repository security policy or scanning adds a smaller transparency gap.
67%
Total Score
50
100
80
75
The registry lists one maintainer, which creates a limited visible publishing base. The repository is also owned by the same individual, so this is a capacity concern rather than evidence of a mismatch.
This is the first release, published today, so there is no release cadence or history demonstrating sustained maintenance. That is a meaningful maturity gap, but not evidence of abandonment at this age.
There were zero commits and zero active maintainers in the last three months, but the repository and release are both only hours old. This cannot establish abandonment, though it leaves maintenance unproven.
The repository has no security policy, and repo_tooling reports no security scanning tools. For a new SDK this is a transparency and response-process gap, though it does not by itself make the release unfit.
Version v0.1.0 is an early, non-stable-major release, which signals that the API may still change. It is not marked as a prerelease, providing a small counterpoint but not a track record of stability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
php-http/discovery Version ^1.19 | — | — |
psr/http-client-implementation Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.