The package has a clear MIT license, a substantial README, repository tests, and Psalm security tooling. Its short release history and no commits in the last three months leave maintenance capacity uncertain, while all 34 workflow actions are unpinned.
58%
Total Score
75
88
75
The package is only 142 days old with three releases and a median interval of about 4 days, so it shows initial activity but has not established a long maintenance record.
The repository recorded zero commits and zero active maintainers during the last three months. Because the project is young and its latest release was about four months after collection's reference age, this is a meaningful maintenance concern.
The repository has zero stars, forks, and watchers. This is weak supporting evidence for maturity, but popularity alone does not determine whether a small package is healthy.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
All seven workflows were analyzed without dangerous triggers or audit findings, and none grant top-level write access. However, all 34 action references are unpinned, which weakens build reproducibility and supply-chain control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
php-http/message Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0|^2.0 | — | — |
psr/simple-cache Version ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.