Healthy and reasonable to adopt, with some maintenance caveats. It has recent releases, tests, clear documentation, organizational backing, and an active repository, but all recent commits come from one contributor and both workflows have broad write permissions.
78%
Total Score
83
100
94
83
All seven commits in the last three months came from one contributor, leaving maintenance dependent on a single active developer. Organizational backing partly offsets this risk because the repository belongs to an organization.
The project uses Composer for builds, but no security-scanning tool was detected. This is a transparency and maintenance gap, though the repository still provides tests and a security policy.
Both workflows declare top-level write permissions, which grants broader automation privileges than necessary and increases workflow-impact risk. This is partly mitigated by the absence of detected dangerous workflow patterns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.