The package is licensed, documented, tested, and backed by an active organization-owned repository. Workflow hygiene needs attention: insecure commands were detected and all four action references are unpinned, while recent repository activity is absent.
64%
Total Score
75
89
75
The repository recorded zero commits and zero active maintainers over the last three months, which is a meaningful sign of currently limited maintenance activity.
The repository has zero stars, forks, and watchers, providing no community adoption signal to offset the thin recent activity evidence.
The project uses Make and Composer, but no security scanning tools were detected; this is a modest repository hygiene gap rather than evidence of abandonment.
No security policy was found in the repository, leaving vulnerability-reporting expectations unclear for an API client library.
Both workflows were analyzed successfully with no untrusted checkout or injection sinks, but all four action references are unpinned and a high-confidence insecure-commands finding was reported in CI. These are workflow hygiene risks, not standalone evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0.1 | — | — |
php-http/httplug Version ^2.2.0 | — | — |
php-http/message Version ^1.10.0 | — | — |
psr/http-factory Version ^1.1.0 | — | — |
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.