The repository is backed by a matching organization, includes tests, and has a clear MIT license. Its small footprint and single registry maintainer limit resilience.
58%
Total Score
75
83
50
The package has 14 releases since March 2023, but none in the last 12 months; its previously frequent release cadence has stopped.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap and raising maintenance risk.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities, although this is a hygiene concern rather than evidence of an unsafe release.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all 11 action references are unpinned, leaving the build exposed to moving action revisions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0 | — | — |
php-http/discovery Version ^1.12 | — | — |
php-http/client-common Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.