The generated client has extensive documentation, tests, and an organization-backed repository. Its workflow needs tightening, and the project shows little recent activity, so pin this version only if its API coverage fits your needs.
52%
Total Score
75
92
50
The package has eight releases over 819 days, but none in the last 12 months; the latest release was published in June 2025. This is a meaningful maintenance concern for a generated API client.
The repository recorded zero commits and zero active maintainers in the last three months, which supports the concern that development has stalled. The recent release history does not compensate for this lack of current source activity.
The linked repository has no security policy. This reduces transparency for reporting vulnerabilities, although the organization-backed repository and available tests provide some compensating project evidence.
The sole workflow grants top-level write permissions and uses one unpinned action, which weakens build hygiene. The reported high-confidence template-injection findings are not accompanied by an untrusted trigger or checkout, so they do not independently indicate severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.