The repository is very small, has one registry maintainer, and provides no security policy or scanning. A clear README, tests, MIT licensing, and a matching source repository make the package understandable to adopt.
58%
Total Score
50
83
83
One registry maintainer is listed, and the project is backed by an individual repository owner rather than an organization. This creates a limited continuity buffer if that maintainer becomes unavailable.
The package has 12 releases, but none in the last 12 months; its latest release was nearly two years ago. The short historical release intervals show earlier activity but do not offset the current gap.
The repository had no commits and no active maintainers in the last three months, consistent with the long release gap and suggesting maintenance has stalled.
The repository has 7 stars and 1 fork, indicating a small user and contributor base. Low popularity is supporting evidence of limited external review, not a health verdict by itself.
Composer is used for builds, but no security scanning tools are configured. This is a maintenance and transparency gap for a package handling API credentials.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.