The repository has a matching package name, documentation, tests, and an MIT license, which provide useful baseline transparency. Its small footprint, lack of recent commits, and absent security policy leave little evidence of ongoing maintenance.
18%
Total Score
50
57
75
The package is marked abandoned on Packagist with package-wide scope and no replacement distinct from the listed package, making it unfit to adopt despite the repository remaining available.
This release was published in March 2023, and it is the package's only release; there have been no releases in about three and a half years.
The repository recorded zero commits and zero active maintainers in the last three months, which is consistent with stalled maintenance; its last push was in May 2025.
Composer build tooling is present, but no security-scanning tool was detected, leaving a maintenance and transparency gap for a package that handles external API dependencies.
The repository has no security policy, reducing transparency about how vulnerabilities are reported and handled.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/flysystem Version ^1.0 | — | — |
guzzlehttp/guzzle Version ^6|^7 | — | — |
knplabs/github-api Version ^3.0 | — | — |
http-interop/http-factory-guzzle Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.