The package has a matching Apache-2.0 license, extensive documentation, and read-only, fully pinned CI. Organization backing and frequent releases help, but the project has no security policy and its recent development is concentrated in one contributor.
67%
Total Score
67
83
75
The package is only 6 days old, despite 26 releases and a rapid median interval of about 2 hours 22 minutes; this shows activity but gives little evidence of long-term maturity.
One contributor made all 6 commits in the last 3 months, creating concentration risk; organization ownership provides some maintenance handoff capacity but does not remove the current single-contributor dependence.
There were 6 commits in the last 3 months, indicating recent work, but the activity is modest relative to the package's rapid release history.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
The assessed release is a beta, and all recent releases are prereleases, so compatibility and production readiness are not yet established.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version 7.15.5 | — | — |
symfony/http-client Version 6.4.41 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.