The package includes tests, documentation, release notes, and a repository that clearly matches it. Its dependency footprint is fairly broad and the repository has no security policy, while release and commit activity stopped about 2 years and 9 months ago.
53%
Total Score
50
50
78
83
There were 0 commits and 0 active maintainers in the last 3 months, with the last repository push about 2 years and 9 months ago. This is strong evidence that current maintenance has stopped.
The package declares 11 runtime requirements, including several framework, HTTP, logging, and cache components. This broad footprint increases dependency maintenance and compatibility exposure, although the dependencies fit the SDK's apparent functionality.
The package has only 2 releases, with none in the last 12 months, and the latest release was about 2 years and 9 months ago. This is a meaningful maintenance concern for a stable SDK, though the release history is not completely absent.
The repository has 0 stars and forks and only 1 watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of a broad user or contributor base.
Composer build tooling is present, but no security scanning tools were detected. The build setup is appropriate, while the missing scanning coverage is a modest transparency gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache Version ^4.1 | — | — |
monolog/monolog Version ^1.23 | — | — |
guzzlehttp/guzzle Version ^6.3|^7.0 | — | — |
doctrine/collections Version ^1.5 | — | — |
symfony/http-foundation Version ^4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.