The package is clearly identified, licensed, and easy to inspect, with a small dependency set and no install-time scripts. Its single-person ownership, lack of recent activity, and missing security practices increase the risk of relying on it for new work.
58%
Total Score
50
100
79
75
Only one registry account has publish access. Because the repository is owned by an individual rather than an organization, there is little visible publishing redundancy.
The package and repository are both owned by the same individual account, with no organizational backing shown; this provides less continuity than an organization-supported project.
The package has 18 releases since November 2018, but none in the last 12 months; the latest release was over two years ago, indicating sustained inactivity.
There were zero commits and zero active maintainers in the last three months, consistent with the release gap and indicating that maintenance has effectively paused.
Composer is used for builds, but no security scanning tool is configured. That is a meaningful security-process gap for a package intended to be consumed as a library.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sudiptochoudhury/php-api-client-forge Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.