The focused artifact has a clear README, simple dependencies, and no install-time scripts. Its missing security policy and minimal project activity leave little evidence of ongoing care for a library handling API access.
31%
Total Score
0
100
75
75
This package has only one release, published over 11 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk, despite the stable version.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the package's long release gap and leaving current maintenance un demonstrated.
The repository has 6 stars and 2 forks, providing little community evidence to offset the lack of recent maintenance. Popularity is supporting evidence only, so this remains a caution.
Composer is used for builds, which is appropriate, but no security scanning tooling is present. This is a modest supply-chain hygiene gap rather than a severe risk by itself.
The repository has no security policy. For a package that connects to an external API, this reduces transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.