Documentation and licensing are solid, with a clear package structure and automated analysis. Maintenance remains unproven after a single release, while workflow dependencies are broadly unpinned and include an archived action.
58%
Total Score
75
93
67
The package is 292 days old but has only one release, with no demonstrated release cadence beyond v1.0.0. This leaves ongoing maintenance and compatibility support uncertain.
The repository recorded zero commits and zero active maintainers in the last three months. For a package with only one release, that makes continuing maintenance uncertain.
The repository has no security policy. That is a transparency gap for a library implementing a protocol involving document access, even though automated scanning tools are present.
All 15 analyzed action references are unpinned, and the release workflow uses one archived action with high-confidence medium severity. Workflows were fully analyzed and showed no untrusted checkout or script-injection paths, limiting the risk to hygiene and maintenance concerns.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^1.0 || ^2.0 || ^3.0 | — | — |
loophp/psr17 Version ^1.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0.1 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.