The MIT license, focused dependency set, clear README, and matching source repository provide a usable foundation. It is a brand-new release with no demonstrated commit activity, one registry maintainer, no tests, and no security policy, so long-term support remains uncertain.
62%
Total Score
50
100
83
75
Only one registry maintainer, Trisnawan, is listed. Because the repository is user-owned rather than organization-backed, this indicates a thin apparent maintainer base.
This is the package's first and only release, published today, so there is no release history to demonstrate maturity or sustained maintenance.
The repository has zero commits and zero active maintainers in the last three months. Since the repository is newly created, this is partly explained by its age but still provides no evidence of ongoing maintenance.
Composer is used for builds, but no security-scanning tooling is present. That is a hygiene gap for a package handling API credentials and signed callbacks.
The repository has no security policy. This weakens disclosure transparency, especially for a client that handles secret keys and webhook authentication.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.