The MIT license and focused dependency set make the package straightforward to evaluate and integrate. It lacks a security policy and security-scanning tooling, leaving limited evidence of ongoing security practice.
55%
Total Score
50
100
88
83
The registry namespace and repository owner match, and the owner is an individual account rather than an organization. This supports package identity but provides limited evidence of broader project backing.
The package has only two releases, both published within about seven minutes, and no later release activity across its 159-day age. That gives little evidence of an established maintenance cadence.
The repository recorded zero commits and zero active maintainers during the last three months. Given the package's short history, this is a meaningful but not conclusive sign of slowing maintenance.
Composer is used for build and package management, but no security-scanning tools are present. That leaves less evidence of routine security hygiene.
The repository has no security policy. For an SDK handling API access, this weakens the project's transparency about reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.