Usable with caveats: the repository is active, tested, licensed, and uses sensible tooling, but release activity is sparse and there were no commits in the last three months. Missing security-policy documentation and incomplete workflow permission declarations add smaller maintenance concerns.
68%
Total Score
50
100
89
80
The package has existed for 1,059 days but only 4 releases, with 1 release in the last 12 months and a median interval of about 281 days. This indicates a slow maintenance cadence, though the latest release is current as of the collection date.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Combined with the slow release history, this is the main abandonment-risk signal, despite the repository's current non-archived status.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This is neutral when the project is quiet, but it provides little evidence of an active user or maintainer feedback loop.
The repository has 14 stars, 3 forks, and 1 watcher, indicating limited external adoption. Popularity is only supporting evidence, so this lowers confidence in maturity modestly rather than making the package unsafe.
The repository has no SECURITY.md or other security policy. This is a transparency gap for a maintained API client, although automated scanning provides partial compensation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.