The package includes a useful README, tests, MIT licensing, and no install-time scripts. The repository is not archived and its workflow audit found no high-risk patterns; pin v1.0.0 until a broader maintenance record develops.
62%
Total Score
50
94
67
The repository is owned by an individual account rather than an organization, so there is no organizational backing to offset the concentrated contributor base.
This is a 54-day-old package with only one release, so its maintenance and compatibility record is still unproven.
One contributor made all recent commits, leaving maintenance dependent on a single person with no demonstrated handoff capacity.
The repository has only 2 commits in the past 3 months, which is limited evidence of ongoing maintenance for a new API client.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
psr/http-message Version ^2.0 | — | — |
php-http/discovery Version ^1.20 | — | — |
symfony/serializer Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.