The package includes extensive documentation, repository tests, release notes, and a clear MIT license. Its maintenance record is too new to establish durability, and the repository lacks security-scanning tooling.
72%
Total Score
50
100
88
83
The repository is owned by an individual account rather than an organization, so the single registry maintainer does not have clear organizational backing to offset the thin maintenance history.
The package has only three releases, all published within a few hours on its first day, so there is no established long-term maintenance pattern yet.
The repository reports zero commits and zero active maintainers over the last three months, so sustained maintenance cannot yet be demonstrated; the recent push and two merged pull requests provide only limited compensation.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
The single workflow was fully analyzed, uses read-only job permissions, and has no detected dangerous findings. However, both action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.15.2 || ^8.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.