Its tiny metapackage layout, license, dependency, and organization-backed repository fit its role. The README is clear, install-time scripts are absent, and the workflow audit found no issues.
70%
Total Score
75
100
88
88
The package is brand new, with only 2 releases published within minutes of each other and no longer-term release record. This limits evidence of sustained maintenance.
The repository has 0 commits and 0 active maintainers in the past 3 months; because the package was created today, this is primarily limited evidence rather than proof of abandonment.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest supply-chain hygiene gap, not a severe risk on its own.
The linked repository has no documented security policy. This is a transparency gap, although the small metapackage scope limits its practical weight.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tyhpdef/guzzlehttp-promises-impl Version ~3.0.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.