The MIT license, README, changelog, and exact GitHub release improve transparency. Recent development has paused, with no security policy and both workflow actions unpinned, so maintenance and build hygiene remain concerns.
62%
Total Score
50
100
88
67
The package has 12 releases over roughly 692 days, including two in the last 12 months, but the median interval of about 2 days suggests releases were concentrated in bursts rather than consistently maintained.
The repository recorded zero commits and zero active maintainers during the last three months. This is a concrete sign that maintenance may have slowed, despite the recent release push.
Composer is used as the build tool, but no security scanning tools were detected. The absence of scanning weakens repository hygiene for a package handling API tokens.
The repository has no security policy. That reduces transparency about vulnerability reporting and response expectations for a library that handles access and refresh tokens.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both of its two action references are unpinned. That leaves the build exposed to moving action versions.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.