A modest dependency set and no install-time scripts reduce exposure; organization ownership and a matching, non-archived repository provide useful continuity. The package is small and lightly adopted, so ongoing support may depend on one maintainer.
68%
Total Score
100
100
78
75
The artifact includes a README, but it is only 12 characters and provides almost no consumer guidance. Missing tests and a changelog in the published artifact are normal packaging practice and are not counted against it.
The package has only 2 releases over 444 days, with 1 release in the last 12 months and a median interval of about 118 days. This indicates a small, relatively slow-moving project rather than strong release maturity.
The repository has 0 stars, 0 forks, and 1 watcher, indicating very limited visible adoption. Popularity is supporting evidence rather than a verdict, but it lowers confidence in long-term community support.
Composer is used as a build tool, but no security-scanning tool was detected. The missing scanning is a transparency and maintenance-hygiene gap, not evidence that the release is unsafe.
The repository has no security policy. This leaves vulnerability reporting and response expectations undocumented, creating a modest maintenance-transparency concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ~4.9.0 | — | — |
guzzlehttp/guzzle Version ^7.9.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.