The README, tests, MIT license, and matching repository make adoption transparent. Dependabot and Composer tooling provide useful maintenance support, while the workflow references need tighter pinning.
58%
Total Score
50
94
75
The package has only 4 releases since July 2023 and none in the last 12 months; the latest release was in January 2025, indicating a meaningful maintenance slowdown.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, leaving current maintenance capacity unproven.
No security policy was found in the repository, which reduces transparency for reporting and handling vulnerabilities.
Both workflows were fully analyzed with no high-confidence audit findings, no untrusted checkouts, and no script injection, but all 6 action references are unpinned, leaving avoidable supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
psr/http-message Version ^1.1 | — | — |
symfony/filesystem Version ^6.0 || ^7.0 | — | — |
symfony/http-client Version ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.