Its Apache-2.0 license and matching organization-owned repository improve transparency. The 64-character README and absent security policy leave limited guidance and assurance.
38%
Total Score
50
64
75
The package has had no release in more than 10 years: its latest release was in November 2015, with no releases in the last 12 months. This is strong evidence of abandonment for a maintained API client.
There were no commits and no active maintainers in the last three months, consistent with the long gap since the last release and indicating substantial abandonment risk.
The package includes a README, while absent tests and a changelog are normal for published artifacts under these rules. The README is very short, so consumer guidance is limited.
There has been no issue or pull-request activity in the last month, and two issues remain open. This supports the conclusion that maintenance is currently inactive.
Composer build tooling is present, but no security-scanning tool was detected. For a dependency handling security-assessment APIs, this is a modest assurance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.0.0 | — | — |
guzzle/guzzle Version ~3.9.3 | — | — |
symfony/serializer Version ~2.6.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.