Clear licensing, documentation, tests, and release notes make integration straightforward. The organization provides useful backing, but maintenance depends on one recent contributor and workflow references are not pinned.
74%
Total Score
80
100
89
75
The project has existed for about seven years with 12 releases, but only one release in the last 12 months and a median interval of about 197 days indicate a measured, relatively slow cadence.
All recent commits came from one contributor, creating concentration risk; organization ownership provides some handoff capacity but does not show a second active contributor in this period.
There was one commit in the last three months from one active maintainer, showing recent activity but limited current maintenance capacity.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest gap in repository security hygiene.
The repository has no security policy, which makes vulnerability-reporting expectations less transparent for a client handling API credentials.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^6.3 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.