The README, release notes, MIT declaration, and Composer tooling provide a workable integration path. A single publisher and no security policy leave less visible support and governance if issues arise.
58%
Total Score
50
100
93
50
Only one registry publishing account is listed, leaving limited visible publishing continuity; the repository owner is also an individual rather than an organization.
The package is only 123 days old and has just two releases, both published within about three minutes, so there is little evidence of an established maintenance pattern.
The repository recorded no commits and no active maintainers during the last three months, which weakens confidence that fixes will arrive as the package matures.
The linked repository has no security policy, reducing transparency about how users should report vulnerabilities and how security fixes are handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0|^2.0|^3.0 | — | — |
guzzlehttp/guzzle Version ^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.