It has a stable v2 release, recent release notes, clear licensing, and a small dependency set. The organization backing helps, but the available maintenance and security evidence remains narrow.
72%
Total Score
67
100
94
83
All three-month commit activity comes from one contributor. The organization-owned repository provides some handoff capacity, but no second active contributor is shown.
Only one commit from one active maintainer was recorded in the last three months. Recent release activity partly offsets this, but the direct maintenance evidence is thin.
Composer is used as the build tool, but no security scanning tooling was detected. The missing scanner is a hygiene limitation rather than evidence of an unsafe release.
The repository has no security policy. That weakens vulnerability-reporting transparency for an API client, although it is not by itself evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 || ^8.0 | — | — |
symfony/http-foundation Version ^6.0 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.