The source is a very small SDK with no security policy or scanning, which limits transparency. Organization ownership and a stable release line provide some support, but they do not show current maintenance.
32%
Total Score
50
100
63
83
No declared license, license file, or repository license file was detected. That creates a significant legal and adoption concern for an open-source SDK.
The latest release was in September 2021, with no releases in the last 12 months and only eight releases overall. This strongly raises abandonment risk for a dependency.
The repository had zero commits and zero active maintainers in the three months before collection, consistent with the long release gap. This is strong evidence of inactive maintenance.
The package contains no README, tests, or changelog. Missing tests and changelog are normal for published artifacts, but the missing README is a real documentation gap for a library consumers must integrate.
Composer is used for the build, which is appropriate, but no security scanning tooling is present. This modestly reduces transparency and assurance without proving the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.