Clear documentation, licensing, and release notes make the package easy to assess. Organization backing and recent activity help, but all workflow actions are unpinned and recent commits come from one contributor.
82%
Total Score
83
100
100
100
One contributor made 100% of the 26 recent commits, leaving a meaningful continuity risk; organization ownership provides some ability to hand maintenance off but no second active contributor is shown.
Both workflows use read-only permissions and the audit found no untrusted checkouts, script injection, or high-confidence findings. However, all 12 analyzed action references are unpinned, which leaves avoidable build-reproducibility and action-supply-chain exposure.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-21617 guzzlehttp/oauth-subscriber is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in versions 0.0.0 - 0.8.1. | 0.0.0 - 0.8.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^3.1 | — | — |
guzzlehttp/guzzle Version ^8.1 | — | — |
guzzlehttp/promises Version ^3.0.2 | — | — |
symfony/polyfill-php82 Version ^1.27 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.