The repository has tests, a changelog, release notes, a security policy, and a clear organization owner. Four workflow dependencies are unpinned, and the package is still pre-1.0, so pinning and API stability deserve attention.
82%
Total Score
100
100
81
83
The repository reports zero stars, forks, and watchers. Popularity is only supporting evidence, so this lowers external validation somewhat but does not outweigh the active release and project-structure signals.
The project uses Make and Composer, showing established build tooling. No security-scanning tools were detected, which is a modest process gap for a package handling API integrations.
v0.46.0 is not a prerelease, but the package has not reached a stable major version. Consumers should expect more API change than they would from a 1.x release.
Both workflows were analyzed successfully with no untrusted checkouts, script injection, or auditor findings. However, all four action references are unpinned and one workflow grants top-level write permissions, creating avoidable maintenance and workflow-hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.8 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
php-http/discovery Version ^1.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.