API client for Google's Gemini API
58%
Total Score
75
93
67
The package has 22 releases, but none in the last 12 months; its latest release was about 20 months ago. This materially raises abandonment risk despite the established release history.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with the long release gap and indicating currently inactive maintenance.
No repository security policy was found, leaving vulnerability-reporting expectations unclear. This is a transparency gap, but it is not severe on its own.
All 6 analyzed action references are unpinned, which weakens build reproducibility. However, both workflows were fully analyzed and there are no untrusted checkouts, injection findings, or broad top-level write permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0.2 | — | — |
psr/http-message Version ^1.0.1 || ^2.0 | — | — |
php-http/discovery Version ^1.19 | — | — |
psr/http-client-implementation Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.