The small, coherent artifact has a clear README, matching repository, MIT licensing, and no install scripts. It lacks security scanning and a security policy, so future fixes and security response are harder to assess.
62%
Total Score
100
78
83
The package has two releases, both published on January 5, 2026, and no later release over the following 259 days. That provides little evidence of sustained maintenance.
The repository has 4 stars and 1 fork, showing limited adoption. Popularity is only supporting evidence, but this offers little external confirmation of project maturity.
Composer is used for builds, but no security-scanning tool is configured. That is a transparency and maintenance gap for a package handling networked SDK behavior.
The linked repository is not archived, although its last push was on the same day as the releases and therefore does not offset the limited maintenance evidence.
The repository has no security policy. This makes the expected reporting and response process unclear, particularly for a package that communicates with an external service.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
textalk/websocket Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.