Usable with caveats: this is a clearly licensed, documented, test-backed initial SDK release with organization backing, but it has only one release and no commits or contributor activity in the last three months. The absent security policy and scanning reduce transparency for a package handling GitHub authentication.
62%
Total Score
67
100
78
90
Only one registry publisher is listed, which is a limited operational base, but the repository is owned by an organization, making the short registry list less concerning.
This package is only 140 days old and has a single release, so there is not yet evidence of an established release cadence or long-term maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, despite the package being a young project; this leaves maintenance continuity unproven.
The repository has zero stars, forks, and watchers. This is supporting evidence that the project is unproven, but low popularity alone is not a health verdict for a new package.
The project uses Make and Composer for builds, but it has no detected security scanning tools, leaving a meaningful security-process gap for an SDK that supports access tokens.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
php-http/httplug Version ^2.2 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
symfony/http-client Version 6.4.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.