The project has recent, substantial commit activity, tests, release notes, and a clear package repository. Maintenance is concentrated in one contributor, and both workflow references are unpinned; the organization backing reduces but does not eliminate that continuity concern.
82%
Total Score
83
100
94
83
All 113 recent commits came from one contributor, creating continuity risk; organization ownership provides some ability to hand maintenance off, but no second active contributor is evidenced.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository hygiene gap.
The repository has no security policy, which weakens the documented path for reporting vulnerabilities but is not by itself evidence of abandonment.
The single workflow was fully analyzed, uses read-only permissions, and has no audit findings or untrusted-code sinks. Both action references are unpinned, so their versions are not reproducibly fixed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-http/discovery Version ^1.20 | — | — |
programmatordev/php-api-sdk Version ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.