It has clear documentation, tests, an MIT declaration, organization backing, and security scanning. The narrow dependency set and clean workflow audit help, but there is not yet enough history to establish durability.
62%
Total Score
75
100
94
75
The package is 0 days old with only 2 releases, so there is too little release history to demonstrate sustained maintenance or maturity.
There were 0 commits and 0 active maintainers in the last 3 months, but the repository is only 0 days old; this is insufficient history rather than evidence of abandonment.
No security policy is present, leaving vulnerability-reporting and response expectations undocumented for a package that handles OAuth credentials and tokens.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings, and it scopes permissions at job level. However, all 8 action references are unpinned, leaving CI exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ez-php/contracts Version ^2.0 | — | — |
ez-php/http-client Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.