The project has clear licensing, repository tests, release notes, and security scanning. Its quiet three-month commit window merits monitoring, while the dependency set is modest.
77%
Total Score
50
100
100
50
The repository recorded zero commits and zero active maintainers in the last three months. The recent release partly offsets this, but the short-term silence is a maintenance caution.
No security policy was found in the repository, leaving vulnerability-reporting guidance undocumented. This is a transparency gap but not evidence of abandonment.
All 20 analyzed action references are unpinned, which weakens build reproducibility and action supply-chain control. The audit found no untrusted checkouts, script injection, dangerous triggers, or other reported findings, limiting the impact to caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
php-http/httplug Version ^1.1 || ^2.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
symfony/options-resolver Version ^3.4 || ^4.0 || ^5.0 || ^6.0 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.