The library is well-scoped, documented, tested, and clearly tied to its organization-owned repository. Recent maintenance has paused, while all six workflow actions are unpinned and no security policy is present; pin this version carefully.
70%
Total Score
75
93
75
The repository recorded zero commits and zero active maintainers in the last three months, indicating a recent pause in development despite the package's longer release history.
Composer is used for builds, but no security scanning tools were detected, leaving a security-process gap for a library that handles ACME and certificate operations.
The repository has no security policy, reducing transparency about how vulnerability reports should be handled.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all 6 of its action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0|^2.0|^3.0 | — | — |
lcobucci/jwt Version ^3.3|^4.0|^5.0 | — | — |
guzzlehttp/psr7 Version ^1.7|^2.1 | — | — |
psr/http-message Version ^1.0|^2.0 | — | — |
webmozart/assert Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.