This is a generally healthy, actively released PHP client with a stable major version, a four-year history, regular releases, an unarchived organization-backed repository, tests, CI workflows, and a matching source repository. The main concerns are that commit activity shows no commits or active maintainers in the last 3 months, repository popularity is minimal, no security policy or security-scanning tooling is present, and workflow token permissions are not explicitly constrained; these are meaningful hygiene and maintenance risks but do not outweigh the strong release, repository, and testing evidence.
82%
Total Score
88
100
89
80
No commits and no active maintainers are recorded in the last 3 months, which weakens evidence of ongoing development. This is partly offset by the recent repository push and six releases in the last year, but the direct commit signal remains a maintenance caution.
The repository has 0 stars, 0 forks, and 1 watcher, indicating limited external adoption or visibility. Popularity is supporting evidence rather than a verdict, so this is a modest concern rather than a severe risk.
Composer build tooling is present, but no security-scanning tools are configured. The missing scanning is a repository hygiene gap, though it does not by itself establish that the package is unsafe.
The repository has no security policy. This reduces vulnerability-reporting transparency and is a genuine repository hygiene gap.
All 3 workflows omit top-level token permissions declarations. Although none declares top-level write access, explicitly limiting permissions would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0 | — | — |
smartassert/service-client Version ^8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.