Usable with caveats: the release is clearly licensed, well documented, tested, and backed by an active organization with a recent repository update. However, it has only one release, no observed commit activity yet, and no security policy or scanning configuration, so its long-term maintenance is not established.
68%
Total Score
75
100
88
90
Only one release exists and the package is 0 days old, so there is no demonstrated release cadence or history to establish long-term reliability.
No commits and no active maintainers were observed in the last three months. Because the repository and release are newly observed, this is evidence of unestablished maintenance rather than proof of abandonment, but it remains a caution.
The repository uses Make and Composer build tooling, but no security scanning tools were detected. The missing scanning layer reduces transparency around automated security checks.
No security policy was found in the repository. For a client library that handles bearer-token authentication, this is a genuine transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
grpc/grpc Version 1.82.0 | — | — |
google/protobuf Version 4.33.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.