Healthy and actively released, with solid tests, tooling, and organization backing. The main caveat is that the repository recorded no commits or active maintainers in the last three months, despite recent releases and merged pull requests.
78%
Total Score
75
50
100
80
Seven runtime dependencies are declared, including standard PSR interfaces and related SmartAssert packages. This is a meaningful dependency surface but not unusually large for a PHP client.
Only one account has registry publishing access, which is a narrow publishing base. Organization backing and recent release activity provide some compensation, but administrative access does not establish active maintenance.
There were zero commits and zero active maintainers in the last three months, a significant maintenance warning. Recent releases and merged pull requests partly offset this, but the lack of recent commits still raises abandonment risk.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
All three workflows lack top-level token permissions declarations. No workflow requests top-level write access, but explicit least-privilege settings would provide stronger CI transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0 | — | — |
smartassert/yaml-file Version ^9.0 | — | — |
smartassert/service-client Version ^8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.