The package is clearly licensed and documented, with a stable release and a matching organization-backed repository. Its small footprint and lack of recent commit activity or security policy leave maintenance and transparency concerns.
68%
Total Score
83
100
89
75
There were no commits and no active maintainers in the last three months. For a package whose latest release was also in March, this is a meaningful maintenance concern.
The repository has no stars, forks, or watchers. This is weak supporting evidence for maturity, but popularity is not decisive for a small specialized SDK.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a repository hygiene gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
No GitHub Actions workflows were analyzed, so there are no workflow risks, but this also provides no evidence of automated validation or release controls.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0|^7.9|^7.10 | — | — |
sharpapi/php-core Version ^1.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.