It is MIT-licensed, has tests and a changelog in the repository, and uses read-only workflow permissions. The unpinned container image and missing security policy add avoidable risk.
42%
Total Score
50
100
78
83
This package has only one release, published 441 days ago, with no releases in the last 12 months. That leaves maintenance and release continuity unproven.
The repository had zero commits and zero active maintainers in the last three months. Combined with the single-release history, this is strong evidence that ongoing maintenance is unproven.
All three workflows use read-only permissions and have no untrusted checkout or script-injection findings. However, all 16 action references are unpinned, and the audit found a high-confidence unpinned container image, creating reproducibility and supply-chain hygiene risk.
The registry namespace and repository are owned by the same individual account, with no organization backing shown. This does not prove a problem, but it offers limited evidence of institutional maintenance capacity.
There were no new or closed issues and no pull-request activity in the last month. This is consistent with an inactive project, though the open-issues count is unknown.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.9.1 || ^2.6.3 | — | — |
psr/http-client Version ^1.0 | — | — |
guzzlehttp/promises Version ^1.5.3 || ^2.0.3 | — | — |
symfony/deprecation-contracts Version ^2.2 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.