The package is clearly licensed, documented, backed by an organization, and has repository tests. Its maintenance record is too short to establish maturity, and the repository has no security policy or scanning tool.
68%
Total Score
75
100
79
75
This is the package's first release, published less than a day ago, so there is no release track record yet. That limits evidence of maintenance and maturity rather than showing abandonment.
No commits or active maintainers were observed in the preceding three months. Because the repository is newly created, this is mainly a lack of proven maintenance capacity rather than evidence of a collapsed project.
Composer build tooling is present, but no security-scanning tools were detected. For an SDK handling API credentials and event data, that is a modest transparency and maintenance gap.
The repository has no security policy. This does not show a vulnerability, but it leaves vulnerability reporting and response expectations undocumented.
Version 0.1.0 is an early development release, so its API and behavior may change as the project matures.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.