The source includes tests, a clear README, and a declared MIT license. All four workflow actions are unpinned, and the repository has no security policy; the project is small but not archived.
52%
Total Score
50
100
86
75
This is the package's only release, published over three years ago, with no releases in the last 12 months. That leaves maintenance and compatibility uncertain despite the repository remaining available.
The repository had zero commits and zero active maintainers in the last three months. Combined with a single historical release, this is a meaningful sign of slowing maintenance.
Composer is used for the build, but no security-scanning tooling was detected. The missing scanner is a transparency and hygiene gap, not proof of unsafe code.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a moderate transparency gap for a client library handling API credentials.
The audit covered both workflows without failures and found no dangerous triggers or sinks, but all four action references are unpinned. That weakens reproducibility and update integrity without making the package unfit on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.4.5 | — | — |
illuminate/container Version ^9.22 | — | — |
illuminate/collections Version ^9.21 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.