It has a clear README, tests, an MIT license, and an organization-backed repository. The workflow leaves all 8 action references unpinned and the project has no security policy.
68%
Total Score
75
100
94
75
The package was released only about 1 hour 25 minutes before collection and has just two releases, so there is little evidence of sustained maintenance or maturity.
The repository has no commits or active maintainers recorded in the last 3 months. Because the package is only hours old, this mainly reflects insufficient history, but it still limits evidence of maintenance capacity.
No security policy is present, leaving vulnerability-reporting expectations unclear for a package that handles webhook signatures and delivery.
The single workflow was fully analyzed with no dangerous audit findings, and it scopes permissions at job level. However, all 8 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ez-php/http Version ^2.0 | — | — |
ez-php/queue Version ^2.0 | — | — |
ez-php/contracts Version ^2.0 | — | — |
ez-php/http-client Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.