It has regular releases, repository tests, release notes, and organization backing. The package is clearly tied to its repository and has no install-time scripts, but its pre-1.0 status leaves less stability assurance.
73%
Total Score
83
100
89
75
All five recent commits came from one contributor, concentrating practical maintenance knowledge and increasing continuity risk. Organization backing partly compensates for that concentration.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository hygiene gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
Version v0.3.6 is not a stable major release, so compatibility may change before 1.0 despite the absence of prereleases.
The single workflow was fully analyzed, uses read-only permissions, and has no dangerous triggers or audit findings. However, all three action references are unpinned, so their resolved code can change without a workflow edit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.10 | — | — |
netresearch/jsonmapper Version ^5.0.1 | — | — |
guzzlehttp/oauth-subscriber Version ^0.8.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.