This release is usable and reasonably transparent: it has a five-year history, 11 releases with five in the last 12 months, a non-prerelease version, a matching repository, documented usage, source tests, and a license file. However, maintenance capacity is uncertain because the repository has had no commits or active maintainers in the last three months, the project has negligible adoption signals, and it lacks both security scanning and a security policy. The generated-SDK structure and recent release activity partly offset the absence of recent repository commits, but this remains a package to adopt with some maintenance and security-process caution.
68%
Total Score
63
100
83
90
The repository is owned by a user account rather than an organization, so there is no demonstrated institutional backing. This makes the zero recent commit activity more consequential than it would be for a clearly organization-owned project.
The repository recorded 0 commits and 0 active maintainers in the last three months, which is a meaningful maintenance concern. Recent registry releases provide partial compensating evidence, especially for a generated SDK, but do not demonstrate ongoing source development.
There are no open issues or pull requests and no activity in the last month. This avoids an unresolved-work backlog, but it also provides no evidence of an active user or contributor community.
The repository has only 1 star, 0 forks, and 1 watcher, indicating very limited external adoption. Popularity is supporting evidence rather than a decisive health verdict, but this reduces confidence in community resilience.
Composer is used as a build tool, which supports reproducible package structure, but no security scanning tools are configured. The missing scanning process is a security-hygiene gap rather than evidence of maliciousness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.4.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.