Strong documentation, tests, licensing, and organization backing improve adoption confidence. The workflow uses unpinned actions, and the project has no security policy or scanning coverage.
62%
Total Score
67
100
81
75
Five releases in 27 days show active initial publishing, but the package is very new and has little long-term maintenance history.
One contributor made all two recent commits, leaving maintenance concentrated in a single individual; organizational ownership provides some handoff capacity but does not remove the concern.
Only two commits were recorded in the last three months, so observed maintenance activity is limited despite the recent release activity.
The repository name does not match the package name and its README does not mention this package, creating a real risk that the linked source is not clearly tied to the published artifact.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.