This release is usable and reasonably transparent, with a linked, matching repository, a substantial README, tests in both the artifact and repository, a healthy package structure, regular release activity, no deprecation, and no install-time lifecycle scripts. However, the package remains pre-1.0, the repository shows no commits or active maintainers in the last 3 months, has no security scanning or security policy, and has negligible adoption signals, so maintenance continuity and security-process maturity are meaningful concerns. Depend on it only if you are comfortable monitoring the repository and upgrading or replacing it if activity declines.
68%
Total Score
50
100
83
90
The repository is owned by an individual user rather than an organization, so the project appears to rely on a narrow ownership base and has less institutional backing.
No commits and no active maintainers were observed in the last 3 months, which is a meaningful maintenance-continuity concern despite the recent registry release activity.
There are no open issues or pull requests and no recent issue or pull-request activity. This is not evidence of abandonment by itself, but it provides little evidence of an active support community.
The repository has zero stars and forks and only one watcher, indicating very limited visible adoption; this is supporting caution rather than a decisive health failure for a small SDK.
Composer is used as a build tool, but no security scanning tools are configured, leaving a security-process maturity gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.4.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.