This release appears healthy and suitable for dependency use: it is a stable, non-deprecated version with 23 releases over roughly 20 months, 18 releases in the last 12 months, and a median release interval of about 12 days. The repository is active, organization-backed, correctly associated with the package, not archived, and uses Composer plus CodeQL; recent activity includes 11 commits and 7 merged pull requests in the last 3 months. The main concerns are that the repository's recent commits are entirely attributed to a release bot, the artifact and repository report no tests, no security policy is present, and workflows lack top-level permission declarations. These are meaningful hygiene and resilience gaps, but they do not outweigh the strong release cadence, active repository state, and organization backing.
82%
Total Score
90
100
94
80
The package includes a README and changelog, and the repository uses GitHub Releases, but neither the artifact nor repository reports tests. For an API client, the missing test evidence is a maintenance and regression-risk gap.
All 11 recent commits came from one contributor, semantic-release-bot, giving the observed activity a weak human bus factor. Organization backing partly mitigates handoff risk, but the signal still warrants caution because no human contributor activity is shown.
No SECURITY.md or equivalent security policy was found, leaving vulnerability-reporting and response expectations less transparent.
All three workflows lack top-level permission declarations, although none declares top-level write permissions and two use job-level permissions. Explicit least-privilege declarations would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.