The repository includes tests, release notes, security scanning, and a security policy. GitHub Actions use an unpinned container image and all 12 action references are unpinned, so build hygiene needs attention.
58%
Total Score
75
94
100
The package has 9 releases since January 2020, but no releases in the last 12 months and the latest release was nearly three years ago, indicating stale maintenance.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long gap since the latest release and raising abandonment risk.
All 12 analyzed action references are unpinned, and a high-confidence audit found an unpinned container image in semgrep.yml. No untrusted checkout or script-injection path was found, limiting this to a hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.