The package is small and pre-1.0, with four runtime dependencies and limited repository security tooling. MIT licensing, organization backing, regular registry releases, and repository tests provide useful support; pin this version and verify maintenance before upgrades.
64%
Total Score
50
50
72
75
The repository recorded zero commits and zero active maintainers in the past 3 months, which weakens evidence of ongoing maintenance despite the recent release history.
Four runtime dependencies create a moderate transitive maintenance surface for this small client library, with no development dependencies declared.
The artifact includes a short README, while repository tests are present; the README is mostly a generic Composer template and offers little consumer guidance.
The repository name matches the package, reducing identity concerns, but its README does not mention the package and is only a generic template.
The repository has zero stars and forks and one watcher; popularity is only supporting evidence, but these counts provide little external adoption signal.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
francerz/http Version ^0.4 | — | — |
francerz/crypto Version ^0.1.0 | — | — |
francerz/oauth2-client Version ^0.3.2 | — | — |
tecnm-dpii/cvu-api2-core Version ^0.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.