The package includes tests, a clear README, release notes, a license, and a small runtime dependency set. Its organization backing and recent repository activity are reassuring, though maintenance is concentrated and workflow references are not pinned.
76%
Total Score
67
100
67
All one commit in the last three months came from a single contributor, so observed maintenance is concentrated. The organization-owned project provides some capacity for handoff, but the current activity still leaves a thin operational base.
One commit from one active maintainer in the last three months shows some recent maintenance, but the activity level is light. The recent release and organizational backing partly offset the limited cadence.
No repository security policy was found. This is a transparency gap for reporting vulnerabilities, but it is not by itself evidence of abandonment or unsafe code.
Both workflows were analyzed successfully and had no reported audit findings or untrusted checkouts; the pull_request_target trigger is not dangerous on its own. However, all 9 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.