This is a healthy, mature release with a long history since 2013, 80 releases, nine releases in the last 12 months, and a recent stable release. The linked EasyPost organization repository is active, unarchived, correctly associated with the package, and shows recent commits from three contributors, issue/PR resolution, CI tooling, a security policy, and no analyzed dangerous workflow patterns. The main reservations are that the repository has no dedicated security-scanning tool and its CI workflow does not declare top-level token permissions; these are configuration and transparency gaps rather than evidence of abandonment. The package artifact also omits tests, but repository tests and a changelog compensate for that artifact-level omission.
88%
Total Score
100
100
94
90
The project uses Just and Composer build tooling, but no security-scanning tools were detected. The build setup is positive, while the missing security scanning is a modest hygiene gap.
The only workflow lacks top-level token permissions, and no read-only permissions declaration was detected; this weakens CI hardening and warrants caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.