Three months without commits raises maintenance risk, and all five workflow actions are unpinned with high-confidence template-injection findings. Regular releases, tests, release notes, licensing, security policy, and organization backing provide meaningful counterweight.
72%
Total Score
75
100
75
A post-install-cmd script runs during installation. Its presence warrants some caution because install-time behavior affects consumers, although this signal does not show that the script is unsafe.
The repository shows 0 commits and 0 active maintainers in the last 3 months, despite the recent release, leaving some uncertainty about ongoing development between releases.
All 5 action references are unpinned, and the audit found three high-confidence template-injection findings. The workflows have no untrusted checkout or dangerous trigger sink, so these are workflow hygiene concerns rather than a severe standalone dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 || ^2.0 | — | — |
psr/simple-cache Version ^1.0 || ^2.0 || ^3.0 | — | — |
guzzlehttp/guzzle Version ^6.5 || ^7.0 || ^8.0 | — | — |
jumbojett/openid-connect-php Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.