The workflow uses read-only job permissions and the package has a clear README, matching license files, and repository tests. Its security documentation is incomplete, and the very young project has not yet demonstrated broader maintenance capacity.
64%
Total Score
75
92
50
The package is only 5 days old, despite 12 releases in that period; this shows active initial work but provides little evidence of sustained maintenance.
One contributor made all 18 recent commits, leaving no demonstrated backup for maintenance or handoff.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
The workflow is fully analyzed, uses read-only permissions, and has no reported audit findings, but all 3 referenced actions are unpinned, leaving avoidable build-reproducibility risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.