Documentation is present and the MIT license is clear. The organization-backed project has little adoption and no automated security scanning, limiting confidence in future maintenance.
67%
Total Score
75
100
83
50
The package has only four releases and none in the last 12 months; the latest registry release was about 17 months before collection. This is a meaningful maintenance concern, although the repository was pushed more recently.
No commits and no active maintainers were recorded in the three months before collection. This recent inactivity weakens confidence in ongoing maintenance, despite the more recent repository push shown elsewhere.
The repository has one star, zero forks, and two watchers, indicating very limited external adoption. Popularity is supporting evidence rather than a decisive health verdict, so this is a mild concern.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning reduces supply-chain transparency and maintenance assurance.
The repository has no security policy. For a client library handling API authorization and tokens, this is a genuine transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.0 || ^7.0 | — | — |
symfony/http-foundation Version ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.