A solid test suite, clear licensing, and matching source repository improve day-to-day confidence. Recent releases help, but no commits in the last three months, fully unpinned workflow actions, and no security policy leave maintenance and build-integrity concerns.
65%
Total Score
50
50
94
83
Ten runtime dependencies, including several framework and Symfony components, increase the dependency surface and transitive maintenance burden for a small client library.
The registry namespace and repository owner match, but the owner is an individual account rather than an organization, so the project has limited visible institutional backing.
The repository recorded zero commits and zero active maintainers over the last three months, a meaningful sign of currently limited development activity despite recent registry releases.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Version v0.1.13 is not a prerelease but remains below major version 1, so API stability may be less established than for a mature major release.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache Version ^4.3|^5.0|^6.0|^7.0 | — | — |
symfony/polyfill Version ^1.26 | — | — |
guzzlehttp/guzzle Version ^6.5|^7.3 | — | — |
composer/ca-bundle Version ^1.2 | — | — |
illuminate/support Version ^6.0|^7.0|^8.0|^9.0|^10.0|^11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.