Unpinned workflow actions and the absence of security scanning leave room for avoidable maintenance risk. The repository includes tests and documentation, while the organization backing and clean registry status are reassuring.
68%
Total Score
83
100
89
75
The package is only 0 days old, with three releases published within about 24 hours, so there is not yet enough history to demonstrate sustained maintenance.
There are no commits or active maintainers recorded over the last three months. Because the repository is newly created, this primarily shows that a long-term maintenance record has not yet been established.
The project uses Composer, but no security scanning tools were detected. That is a modest transparency and upkeep gap for a package handling authentication flows.
The repository has no security policy. For an SSO client, this makes vulnerability reporting and response expectations less clear.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all 6 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.