The package has a clear MIT license, substantial documentation, tests, and a matching organization-backed repository. Missing security policy and six unpinned workflow actions reduce transparency and build reproducibility.
61%
Total Score
100
100
79
50
Only two releases were published, both within about 16 hours, and there have been no releases in the last 12 months despite the package being about 500 days old. This is a meaningful maintenance concern for an API client.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance gap rather than a severe risk.
The linked repository is not archived, although its last push was about 500 days ago, consistent with the release-history concern.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
All three workflows were analyzed successfully with no high-confidence audit findings or untrusted-checkout and script-injection issues. However, all six action references are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
saloonphp/saloon Version ^3.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.