The package is a small, early-stage library with limited evidence of ongoing maintenance and weak consumer documentation. Its release workflow also uses unpinned actions, including an archived action, which adds avoidable supply-chain hygiene risk.
42%
Total Score
33
50
57
50
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the initial release burst and raising abandonment risk.
Eight runtime dependencies create a meaningful dependency surface for a small SDK, although the signal does not show unusual or clearly excessive dependencies.
Only one registry account can publish releases. The repository is user-owned rather than organization-backed, so there is little evidence of redundant publishing capacity.
The package has no README, tests, or changelog, which weakens consumer guidance and project transparency. The exact version does have a GitHub release, partly compensating for the missing changelog, while absent tests are normal for published artifacts but the missing README matters for a library.
The package and repository are owned by the same individual account, not an organization, so there is no observed organizational backing to offset the thin maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amphp/file Version ^3 | — | — |
amphp/http Version ^2.1 | — | — |
crell/serde Version ^1.3 | — | — |
amphp/http-client Version ^5.3 | — | — |
symfony/serializer Version ^7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.