It has a usable README, tests, changelog, and an MIT license in the artifact. The linked repository is quiet and does not identify this package, so pinning this release carries meaningful maintenance and provenance risk.
45%
Total Score
50
80
75
Only three releases exist, with none in the last 12 months; the latest release was published more than three years ago, indicating possible abandonment.
The repository has had zero commits and zero active maintainers in the last three months, consistent with the long release gap and limited evidence of ongoing maintenance.
The repository name does not match the package name and its README does not mention the package, creating a meaningful concern that the linked source may not belong to this release.
The repository has no security policy. This is a transparency and response-process gap, although the package has an identified MIT license and no malware finding is being inferred here.
The single analyzed workflow has no top-level permissions block and all three action references are unpinned. The audit found no high-confidence dangerous findings, but unpinned actions weaken build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pimple/pimple Version ^3.5 | — | — |
guzzlehttp/guzzle Version ^7.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.