Healthy and actively maintained, with a clear README, stable releases, and an organization-backed repository. The main caveats are that one contributor made all 14 recent commits, and the repository has no tests or security policy.
78%
Total Score
80
100
83
90
The release includes a substantial 12,454-character README, which is important for a client library; the absence of tests and a changelog in the published artifact is normal packaging practice, while the repository also reports no tests.
All 14 commits in the last three months came from one contributor, leaving a low individual bus factor; organization ownership provides some handoff capacity but no second active contributor is shown.
There are no open issues or pull requests and no issue or pull-request activity in the last month. This does not show unresolved maintenance problems, but it also provides little independent evidence of community engagement.
The repository has zero stars, forks, and watchers, so there is little public adoption evidence; this is supporting context rather than proof that the package is unsafe or abandoned.
Composer is used for builds, but no security-scanning tool is configured. This is a transparency and defense-in-depth gap, not evidence of maliciousness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.8 | — | — |
wexample/php-helpers Version >=4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.