The README, tests, MIT license, and minimal runtime dependencies provide a solid foundation. Organization backing and a second active contributor help offset the limited security and operational evidence.
64%
Total Score
100
100
75
75
The package is only 46 days old, with two releases published within about two hours and no later release activity observed. That leaves maintenance longevity unproven.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but this provides little external adoption or review evidence for a new package.
Composer is used for builds, but no security scanning tools were detected. For an SDK handling API credentials and postbacks, this is a modest transparency gap.
The repository has no security policy. That makes vulnerability reporting and response expectations unclear for a package intended for server-side integrations.
The latest release is v0.1.1 rather than a stable major version, so the public API may still change. It is not marked as a prerelease, which provides some compensation.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.