The package includes tests, a clear README, a matching BSD-3-Clause license, and automated security scanning. Its small publication history and inactive recent development leave limited evidence of sustained support.
58%
Total Score
75
100
93
100
This is the only release after 106 days of package age, so there is little release history to demonstrate sustained maintenance.
The repository had zero commits and zero active maintainers in the past three months, which is meaningful abandonment risk for a package whose README says it is still under development.
All 9 analyzed action references are unpinned, and the audit found a high-confidence unpinned container image in semgrep.yml. The workflows were fully analyzed and have no untrusted checkout or script-injection findings, which limits the concern but does not remove the reproducibility risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0||^2.0 | — | — |
guzzlehttp/guzzle Version ^7.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.