Documentation, tests, and licensing give consumers a solid starting point. Because this is the only release, maintenance capacity is unproven; workflow hygiene also needs tightening before broad adoption.
64%
Total Score
75
100
94
63
A post-autoload-dump lifecycle script is present. This is an install-time behavior worth noting, but the signal provides no evidence that it is unsafe or unusually broad.
The repository is owned by an individual account rather than an organization, so the project has a narrower visible backing structure; this is not inherently unhealthy for a small package.
This is the package's first and only release, published 0 days ago, so there is no demonstrated release cadence or maintenance track record yet.
No repository security policy was found, leaving vulnerability-reporting expectations unspecified for an SDK that handles API credentials.
All 12 action references are unpinned, and the audit found a high-confidence bot-conditions issue in the Dependabot auto-merge workflow. There are no untrusted checkouts or script injections, which limits the immediate severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
saloonphp/saloon Version ^3.10||^4.0 | — | — |
illuminate/contracts Version ^11.0||^12.0||^13.0 | — | — |
saloonphp/cache-plugin Version ^3.0 | — | — |
saloonphp/pagination-plugin Version ^2.0 | — | — |
saloonphp/rate-limit-plugin Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.