Regular releases, 74 commits in three months, and two active contributors show current maintenance. Apache-2.0 licensing, tests, release notes, and organization backing add useful transparency, while workflow permissions and a high-confidence bot-condition finding warrant care.
82%
Total Score
100
100
100
67
post-install-cmd and post-update-cmd scripts run during dependency operations, creating some additional installation-time behavior to review even though the signal does not show harmful actions.
No security policy was found, leaving vulnerability-reporting expectations unclear. This is a modest transparency gap rather than evidence of abandonment.
All three workflows were analyzed and all 11 action references are pinned, with no untrusted checkout or script-injection findings. However, a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow, and two workflows grant top-level write permissions, creating a meaningful automation-hygiene caveat.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/cache Version ^3.0 | — | — |
nyholm/psr7 Version ^1.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.