Usable with caveats: this is a well-documented, licensed first release with an active-looking organization-backed repository, but it has no demonstrated release history or commit track record yet. The absence of security scanning and a security policy adds a smaller transparency concern.
68%
Total Score
75
100
78
90
Only one release exists and the package is less than one day old, so there is no track record demonstrating sustained maintenance or release reliability.
There are zero commits and zero active maintainers recorded over the past three months, but the repository and release are newly created, so this is limited evidence rather than proof of abandonment.
The repository has zero stars, forks, and watchers, which is consistent with a package released less than one day ago but provides no independent adoption evidence yet.
Composer build tooling is present, but no security scanning tools are configured; this is a transparency and maintenance gap for a newly published package.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
webmozart/assert Version ^1.9.1 || ^2.0 | — | — |
php-http/discovery Version ^1.19 | — | — |
php-http/client-common Version ^2.2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.