The repository is a very small seven-file project with no tests or security policy. Organization backing and a non-archived repository provide some continuity, but maintenance evidence remains limited.
62%
Total Score
75
81
67
The artifact and repository each contain only seven files, including three source files. This keeps the project simple, but provides little visible project structure for a dependency intended as an API client.
The package includes a README, but it is only 20 characters long, and both the package and repository report no tests or changelog. The tiny API surface makes absent packaged tests understandable, but the repository still offers limited verification and documentation.
Only two releases have been published, with one release in the last 12 months and a median interval of about 119 days; this indicates a sparse but not abandoned release history.
There were zero commits and zero active maintainers in the last three months, which weakens evidence of current maintenance. The repository was pushed recently according to repository_archived, so this is a concern rather than proof of abandonment.
Composer build tooling is present, but no security scanning tools are configured. This leaves a modest transparency and maintenance gap, partly offset by the project's small scope.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.9.0 | — | — |
guzzlehttp/guzzle Version ^7.9.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.