The repository includes tests, a changelog, and substantial documentation, with organization backing and three merged pull requests supporting active development. Pin v0.2.0 while the project establishes a longer maintenance record and pins its workflow actions.
68%
Total Score
75
75
50
The package was first released today and has three releases so far, including this version. That shows active initial development but provides little evidence of long-term maintenance.
No commits are recorded over the last three months, but the repository is brand new and was pushed recently; three pull requests were merged in the last month. The short history limits confidence without showing abandonment.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear. This is a modest transparency gap for a package handling AI-provider integrations.
v0.2.0 is not a stable major release, so compatibility may change under the documented 0.x policy. It is not marked as a prerelease, which partly offsets the concern.
The single workflow was fully analyzed, uses read-only permissions, and has no untrusted checkout or injection findings. Both of its action references are unpinned, leaving avoidable supply-chain drift risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1|^2.0|^3.0 | — | — |
symfony/yaml Version ^6.4|^7.0|^8.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
psr/http-message Version ^1.1|^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.