Its workflows use read-only job permissions, and the package includes a substantial README and matching source tree. The organization-backed project has no security policy and uses unpinned action references, so operational hygiene is only moderate.
65%
Total Score
75
88
50
The package was first released today and has only two releases, so there is not yet enough history to demonstrate sustained maintenance. Its stable v1.0.1 version provides some maturity signal but does not offset the lack of track record.
The repository records zero commits and zero active maintainers over the last three months. Because the project is brand new, this is limited evidence rather than proof of abandonment, but maintenance capacity is not yet demonstrated.
The linked repository has no security policy, leaving vulnerability-reporting expectations unclear for an API client. The repository is organization-backed, but that does not replace a published security process.
All 29 analyzed action references are unpinned, which weakens build reproducibility. Both workflows use read-only permissions, and the cache-poisoning finding has low confidence, so this is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.