The package includes a useful README, repository tests, and a matching MIT license. Its four workflow actions are unpinned, and the repository lacks a security policy, adding maintenance and supply-chain hygiene concerns.
52%
Total Score
50
100
88
75
This is the only release, published over six years ago, with no releases in the last 12 months. That strongly limits evidence of continued maintenance.
The repository recorded no commits in the last three months and has no active maintainers in that period; its last push was over five years ago. This is a substantial abandonment concern.
The linked repository has no security policy. For a small package with no other reported security tooling, this reduces transparency and makes vulnerability reporting less clear.
All four analyzed action references are unpinned, which weakens build reproducibility and update control. However, the workflow has no untrusted checkout, script-injection, dangerous trigger, or high-confidence audit finding, so this remains a hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
eightpoints/guzzle-bundle Version ^8.0.1 | — | — |
ion-bazan/aliyun-http-signer Version ^0.2 || ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.