The package has a clear MIT license, extensive documentation, tests, matching source repository, and organizational backing. Recent commit activity is absent, while all two workflow action references are unpinned, leaving maintenance and build-reproducibility concerns.
68%
Total Score
50
100
75
67
The repository has zero commits and zero active maintainers in the last three months, a concrete warning that maintenance may have stalled after the recent release burst.
Eight releases in the last 12 months show active initial delivery, although the short package age and closely spaced releases provide limited evidence of long-term stability.
One star and no forks or watchers provide little evidence of broad adoption, though popularity is supporting evidence rather than a requirement for a focused testing library.
Composer is used as the build tool, but no security-scanning tool is reported, leaving a modest repository hygiene gap.
The repository has no security policy, reducing transparency about how dependency or vulnerability reports are handled.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.0 | — | — |
google/apiclient Version ^2.15 | — | — |
guzzlehttp/guzzle Version ^7.4 | — | — |
google/apiclient-services Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.