Documentation and packaging are solid, and the organization-backed repository is active in setup. The release is too new to establish maintenance capacity, while workflow references are not pinned and no security policy is present.
68%
Total Score
50
83
50
This is the package's first release, published today, so there is no release history or cadence yet; that limits evidence of sustained maintenance but is expected for a new project.
There were no commits or active maintainers in the last 3 months. Because the release is brand new, this is weak evidence rather than proof of abandonment, but it leaves maintenance capacity unestablished.
The repository has no security policy. That reduces vulnerability-reporting transparency for a package that handles HTTP requests, authentication, tokens, and event delivery.
v0.1.0 is not a stable major release, which signals an early API and limited maturity; it is not marked as a prerelease.
The single workflow was fully analyzed and uses read-only permissions with no high- or medium-confidence findings, but all 6 of 6 action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
php-http/discovery Version ^1.19 | — | — |
psr/http-client-implementation Version 1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.