The README, tests, MIT licensing, and modest dependency set make integration straightforward. Ongoing maintenance is the main concern, with no recent activity and no published security policy; pin this version if its API meets your needs.
55%
Total Score
67
100
89
83
The package has made no releases in the last 12 months, and its latest release was about three years ago. Its eight releases over nearly eight years show some history, but the current gap weakens confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with roughly three years since the last push. This is a meaningful abandonment concern even though the repository remains available.
There are two open issues and one open pull request, with no issues or pull requests closed in the last month. The small backlog is not severe, but the lack of recent resolution reinforces the maintenance concern.
Composer build tooling is present, but no security scanning tools were detected. For a client handling API credentials, that is a modest transparency and maintenance gap.
The repository has no security policy. This leaves vulnerability reporting and response expectations undocumented, which matters for a library used to access an external API.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
guzzlehttp/guzzle Version ^6.3 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.