The small source tree is clearly tied to the package, and the release includes notes and a license. There is no security scanning or security policy, adding transparency and maintenance concerns.
46%
Total Score
50
80
50
Only two releases were published, both in March 2024, with no releases in the past 12 months. That limited history and prolonged inactivity raise abandonment concerns.
The repository recorded no commits and had no active maintainers in the past three months, consistent with roughly two years and six months since the last push. This is a meaningful maintenance risk.
Composer is used for the build, which supports reproducible packaging, but no security scanning tooling is present. For a small API client this is a hygiene gap rather than a severe risk.
The repository has no published security policy. This reduces transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.