The README, generated tests, and Composer build make the SDK straightforward to inspect. Expect little ongoing support, and verify that the MIT/Unlicense licensing mismatch is acceptable before adopting it.
52%
Total Score
50
71
50
Only two releases were published, both in October 2023, with no releases in the following nearly three years. This is strong evidence of limited ongoing maintenance for a library dependency.
The artifact contains a license file and the repository also has one, but the manifest declares Unlicense while the detected file is MIT. That mismatch creates a real licensing clarification risk.
The repository recorded no commits and no active maintainers in the last three months, consistent with the release history showing activity ended nearly three years ago.
Composer is used for the build, but no security scanning tools are present. This is a modest transparency and maintenance gap rather than evidence that the release is unfit.
The linked repository has no security policy. For an SDK handling API access, this reduces transparency around vulnerability reporting, though it is not by itself a severe dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.