Usable with caveats: it is a mature, licensed package with organization backing, tests, and a current release, but recent development activity is absent and repository security practices are limited.
68%
Total Score
75
100
89
50
The repository recorded zero commits and zero active maintainers in the last three months. The current release and recent push provide some compensating evidence, but ongoing development capacity is still uncertain.
The repository has only 5 stars and 11 forks, indicating a small user and contributor footprint. Low popularity is supporting caution rather than a severe concern because the package has organization backing and a long release history.
Composer build tooling is present, but no security-scanning tool was detected. This is a transparency and maintenance gap, not evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. The gap lowers transparency but is not independently severe for this small library.
The single workflow has no top-level token-permissions declaration. No write permissions or dangerous workflow patterns were detected, but explicit least-privilege settings would provide better CI hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3||^7.15 | — | — |
traderinteractive/util-arrays Version ^3.1||^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.