Long-term maintenance is unproven because this is a brand-new project with one release. The repository has tests, a changelog, matching documentation, and Dependabot, but its workflows use an unpinned container image and lack a security policy.
64%
Total Score
50
92
50
The package has only one release and is hours old, so there is not yet enough history to establish durable maintenance or release stability. Its age makes the absence of older releases expected rather than evidence of abandonment.
No commits or active maintainers were recorded in the last three months, but the repository was created and pushed only hours ago. This limits confidence in long-term maintenance without proving neglect.
The linked repository has no security policy, leaving the process for reporting and handling security issues unclear. Dependabot provides some compensating security tooling but does not replace a published policy.
All eight action references are unpinned, and the audit found a high-confidence unpinned container image; three workflows also grant top-level write permissions. There is no untrusted checkout or script injection, so this is a hygiene concern rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.