The README documents installation and usage, while the single runtime dependency keeps the package simple to integrate. Its small repository has no tests or security policy, leaving limited evidence of project quality and maintenance discipline.
44%
Total Score
100
57
75
No registry license is declared, and neither the package nor the linked repository contains a recognized license file. This creates a material legal and adoption risk for downstream users.
The package has had no release in nearly two years: its latest release was 22 months ago, with four releases overall and none in the last 12 months. This is strong evidence of slowing maintenance for an early-stage client.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these counters provide little evidence of broad community validation.
Composer is used as the build tool, but no security-scanning tool is configured. The missing scanning is a transparency and hygiene gap, though it is less significant than the release stagnation and missing license.
The repository has no security policy. For a small API client this is a transparency gap, because it gives users no documented route for reporting vulnerabilities or understanding security handling.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.