Clear documentation, tests, licensing, and lightweight dependencies make this easy to evaluate and integrate. The small release history and quiet recent development leave maintenance continuity less certain.
68%
Total Score
75
100
86
50
The package has existed for about 6 years and 7 months but has only 3 releases, with a median interval of about 3 years. One release in the last 12 months is some evidence of continued maintenance, but the overall cadence is sparse.
There were 0 commits and 0 active maintainers in the last 3 months. Combined with the sparse release history, this is a meaningful maintenance-continuity concern.
No security policy was found in the repository. This is a transparency gap for reporting and handling vulnerabilities, though it is not evidence that the package is unsafe.
Version 0.1.2 is not a prerelease, which is positive, but the package remains below a stable major version and may still carry compatibility risk for consumers.
Both workflows were analyzed successfully with no high- or medium-severity findings and no untrusted checkout or script-injection sinks. However, all 14 action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.