Clear documentation, tests, and release notes make integration easier. The source is active, but this registry package is marked abandoned and recent work comes from one contributor; use the listed replacement package instead.
35%
Total Score
83
86
50
Packagist marks the package abandoned at package scope and points to friendsofphp/consul-php-sdk as the replacement. This is a substantial adoption risk even though the assessed release is current.
All four recent commits came from one contributor, giving the project a thin recent contributor base and increasing continuity risk despite organization backing.
The repository has no security policy. For an SDK handling Consul access and ACL tokens, this is a transparency gap.
The single workflow was fully analyzed with no untrusted triggers or injection sinks, but both high-confidence findings concern unpinned container images and all four action references are unpinned. These are meaningful build-reproducibility weaknesses.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2|^3 | — | — |
symfony/http-client Version ^6.4|^7.4|^8.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.