The MIT license, README, tests, and package-to-repository match make the component easy to evaluate. There is no security policy, and the workflow audit found a low-confidence cache-poisoning pattern.
58%
Total Score
50
93
67
One registry maintainer is responsible for publishing, which is a thin operational base for a package with no recent release or commit activity.
The package has 9 releases since November 2019, but none in the last 12 months and the latest was published in August 2023, indicating likely abandonment risk.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and reducing confidence in ongoing maintenance.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
All three workflow action references are unpinned, and the audit reported a low-confidence cache-poisoning pattern; these are workflow hygiene concerns rather than evidence of a severe risk on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.