The package is clearly documented and tested, with a permissive license and no install-time scripts. Its young release history and absent repository security policy leave maintenance and disclosure practices less established.
62%
Total Score
100
78
83
The package is 149 days old but has only one release, with no established release cadence. That makes long-term maintenance less demonstrated.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no external adoption signal for this new package.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a modest transparency gap rather than evidence of unsafe code.
No repository security policy was found, leaving vulnerability reporting and disclosure expectations unspecified.
v0.1.0 is not a stable major release, so compatibility and API maturity are not yet established despite it not being marked as a prerelease.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.