The package includes a license, usage documentation, release notes, and repository tests. Workflow references are entirely unpinned, and one uses an archived action; the missing security policy also reduces transparency.
58%
Total Score
0
63
50
The package has 8 releases since December 2021, but none in the last 12 months; the latest release was May 14, 2023. This materially raises abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the long release gap and indicating no recent maintenance activity.
The project uses Composer, but no security-scanning tools were detected. This is a modest hygiene gap alongside otherwise visible build tooling.
The repository has no security policy. For an API client, this weakens vulnerability-reporting transparency, though it is not evidence of a vulnerability by itself.
All 7 analyzed action references are unpinned, and a high-confidence medium-severity finding identifies an archived action in the test workflow. No untrusted checkout or script-injection path was found, limiting the impact to caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
brokeyourbike/http-enums Version ^2.0 | — | — |
brokeyourbike/http-client Version ^1.0 | — | — |
brokeyourbike/resolve-uri Version ^1.0 | — | — |
brokeyourbike/has-source-model Version ^2.0 | — | — |
brokeyourbike/data-transfer-object Version ^0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.