API client for eKasa API
78%
Total Score
80
89
70
The package defines post-install-cmd and post-update-cmd scripts, creating install-time execution risk and requiring review even though this signal alone does not show malicious behavior.
All recent commit activity is concentrated in one contributor, creating a low short-term bus factor; organization ownership partially compensates by providing potential maintenance handoff capacity.
Only one commit was recorded in the last three months from one active maintainer, showing that recent maintenance is sparse and potentially fragile.
The repository has only 1 star and 4 forks, indicating limited external adoption; this is supporting caution rather than a verdict because popularity is not required for a small stable package.
Composer build tooling is present, but no security scanning tools are configured, leaving a security-hygiene gap in the repository.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/common Version ^3.4 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
symfony/serializer Version ^5.4 || ^6.4 || ^7.0 | — | — |
doctrine/annotations Version ^1.13 || ^2.0 | — | — |
symfony/property-access Version ^5.4 || ^6.4 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.