The package includes tests, release notes, a clear README, and limited runtime dependencies. Its short history leaves maintenance durability unproven, while the release workflow needs tighter permission and checkout controls.
65%
Total Score
75
100
79
50
The package is less than one day old with only two releases, so its release cadence and long-term maintenance record are not yet established.
No commits or active maintainers were recorded in the past three months. Because the package is newly published, this may reflect limited history, but it does not demonstrate sustained maintenance.
The repository uses Composer build tooling, but no security scanning tool was detected. This is a modest transparency gap rather than evidence of unsafe code.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations unspecified for an SDK that handles API keys and file transfers.
Version v0.1.1 is not a prerelease, but the project is still on an initial 0.x line, which signals an early and potentially changing API.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.