Tests, a clear license, and no install-time scripts improve confidence. Organization backing provides some continuity, but the missing security policy leaves fewer documented channels for reporting problems.
70%
Total Score
67
100
88
75
The package has existed for over five years with 20 releases, but only one release in the last 12 months. The latest release was published recently, which partly offsets the slow recent cadence.
All recent repository activity came from one contributor. The organization-owned repository provides some handoff capacity, but no second active contributor is evidenced.
There was one commit in the last three months, showing some recent activity but a limited maintenance pace.
The repository uses Composer, but no security scanning tools were detected. The build tooling is appropriate, while security-monitoring coverage is limited.
The repository has no security policy, leaving reporting and handling expectations undocumented for consumers of an API client.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
illuminate/http Version ^9.0|^10.0|^11.0|^12.0|^13.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.