A Composer plugin to easily apply patches to your project.
61%
Total Score
67
100
88
100
The package is only 31 days old and has one release, so there is little evidence of long-term maintenance or release maturity.
All recent commits came from one contributor. Organization ownership provides some handoff capacity, but current observed maintenance remains concentrated.
There was one commit in the last three months, so recent activity exists but is too sparse to demonstrate an established maintenance cadence.
The repository uses Composer build tooling, but no security scanning tool was detected. The missing scanner is a modest transparency gap rather than evidence of abandonment.
All two workflows were analyzed, but all seven action references are unpinned. The release workflow also has a high-confidence finding that its GitHub App token inherits blanket installation permissions, creating a meaningful release-pipeline hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.