Usable with caveats: it is a small, clearly identified MIT-licensed client with documentation and organization backing, but it has had only one release and no repository activity for about two years. Depend on it only if its API is stable enough for your needs and you can maintain it yourself.
58%
Total Score
75
100
81
50
The package has only one release, published about 2 years and 1 month ago, with no releases in the last 12 months. This is the clearest sign of limited ongoing maintenance, though it may also reflect a deliberately stable client.
There were zero commits and zero active maintainers in the last 3 months, consistent with a repository that has seen no activity since its initial release. This materially raises abandonment and unaddressed-defect risk.
The repository uses Composer, providing normal project build tooling, but has no security-scanning tools. The missing scanning is a modest transparency gap rather than a severe risk for this small library.
The linked repository is not archived, but it was last pushed about 2 years and 1 month ago. The non-archived status is reassuring, while the age of the last update reinforces the maintenance concern.
No security policy is present, leaving the process for reporting and handling vulnerabilities unclear. This matters for an API client, although the organization-backed repository provides some compensating ownership context.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.