The MIT license, small dependency set, and release notes make the artifact straightforward to evaluate. Its tiny community and limited security process reduce confidence in long-term support.
60%
Total Score
50
100
79
75
The repository recorded zero commits and zero active maintainers in the last three months. Although a recent registry release provides some compensating evidence, this still weakens confidence in ongoing maintenance.
The repository name does not match the package name and its README does not mention the package. That weakens confidence that the linked repository is the package's authoritative project source.
The repository has one star, zero forks, and two watchers, indicating a very small external user and contributor base. Low popularity is supporting evidence rather than proof of poor quality, but it limits visible community backing.
Composer is used for builds, but no security-scanning tool was detected. The missing scanner is a modest supply-chain hygiene gap, not evidence of malicious behavior.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap for a client library that may handle authentication tokens.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.