Healthy and suitable to depend on. It has recent, regular releases, active repository work, tests, documentation, and organizational backing; the main caveat is a GitHub workflow with write permissions and pull-request-triggered automation.
88%
Total Score
88
50
100
80
One of two workflows uses pull_request_target, which can require careful handling of untrusted pull requests; no untrusted checkout or script-injection patterns were detected.
The SDK declares 19 runtime dependencies, including several HTTP and serialization interfaces; this is a meaningful dependency surface but is consistent with the package's API-client role.
Only one account has registry publish access, which is a narrow publishing base; the concern is partly offset by the linked organization-owned repository and recent activity.
Both workflows declare top-level permissions, but one grants write access; explicit scoping is better than an undeclared default, though write capability increases automation exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0.0 | — | — |
psr/http-client Version ^1.0.0 | — | — |
php-http/httplug Version ^2.4.0 | — | — |
php-http/message Version ^1.16.0 | — | — |
psr/http-factory Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.