The generated client includes a substantial README, tests, and a repository that clearly matches the package. Its workflows use broad write permissions and unpinned actions, while repository security documentation is absent.
58%
Total Score
50
100
88
50
This is the package's only release, published about 9 months ago, so there is too little history to establish a dependable maintenance pattern.
The repository recorded no commits and no active maintainers in the last 3 months, weakening evidence that issues or API changes will be addressed.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency gap.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
Both workflows grant top-level write permissions and all 4 action references are unpinned. The audit found no untrusted checkout, injection, or high-confidence workflow finding, so this is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.4.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.