Healthy and suitable to depend on. It has recent releases, active development by an organization-backed repository, strong tests and release notes, and no deprecation or install scripts. The repository lacks a security policy and several workflows do not declare top-level permissions, so review the project’s operational security practices before adopting it.
88%
Total Score
100
100
94
80
The repository has only 1 star and 1 fork, showing limited adoption evidence. This is supporting context rather than a decisive concern because the project demonstrates active maintenance and organization backing.
The repository has no SECURITY.md or other detected security policy, leaving vulnerability-reporting expectations unclear for a package intended for server-side integration.
Three of four workflows lack top-level token permissions, and the release workflow grants top-level write access. Although no direct workflow exploit was detected, the permissions configuration is broader or less explicit than ideal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.