Its Apache-2.0 licensing, clear README, and matching source repository improve transparency. Security documentation is absent, and all recent commits come from one contributor, so continuity depends heavily on that maintainer.
78%
Total Score
67
100
94
83
The package and repository are owned by the same individual account, so the single-contributor pattern is not offset by organization-level backing.
All 62 recent commits came from one contributor, creating a meaningful continuity risk despite the strong commit volume.
Composer build tooling is present, but no security-scanning tools were detected, leaving a security-process gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aws/aws-sdk-php Version 3.396.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.