Risky to adopt: the package has had no release or commit activity since July 2018, with no tests or security policy and no meaningful repository adoption. Its MIT licensing, stable version, matching repository, and lack of deprecation or install scripts provide some reassurance, but the long abandonment gap dominates.
46%
Total Score
0
100
71
75
The latest release was July 30, 2018, and there have been zero releases in the last 12 months despite the package being about eight years old. This is strong evidence that maintenance has stopped.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the package's long release gap. The repository is not archived, but it shows no current maintenance activity.
The repository has zero stars and forks and only one watcher. Popularity is not required for a healthy small package, but these values provide no supporting evidence of community use or review.
Composer is used for builds, which is appropriate, but no security scanning tools are configured. This weakens maintenance and vulnerability-monitoring transparency for an authentication-related library.
No security policy is present in the repository. For a package handling HMAC authentication, that is a meaningful transparency gap, even though the absence of a policy is not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3 | — | — |
acquia/http-hmac-php Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.