Usable with caveats: this is a young but clearly packaged SDK with a license, documentation, tests, and recent releases. Maintenance currently depends on one active contributor, and the repository has no security policy or scanning setup.
72%
Total Score
67
100
79
88
The package is only 24 days old with three releases and a median interval of about 4 days, showing active early development but little long-term maintenance history.
All two recent commits came from one contributor, creating a meaningful continuity risk; organization ownership provides some ability to hand maintenance to others but does not demonstrate that this has happened.
The repository had two commits in the last three months, so it is not dormant, but the activity level is still light for a package with limited history.
Composer build tooling is present, but no security scanning tools are configured. This is a transparency and maintenance gap, though it is not severe enough to make the release unfit on its own.
The repository has no security policy, leaving vulnerability-reporting and response expectations unclear for an SDK that handles API credentials and hosted services.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.