MIT licensing, tests, release notes, and a substantial README support basic transparency. The three unpinned workflow actions and absent security policy add maintenance hygiene concerns.
43%
Total Score
0
75
67
The package has 27 releases since September 2020, but none in the last four years; the latest release was in August 2022. This prolonged release gap is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no recent maintenance capacity.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency and maintenance gap for an API client handling credentials.
Version v0.9.8 is not a prerelease, but the package remains below 1.0, and its README explicitly notes that the public API should not be considered stable during initial development.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all three action references are unpinned, so their implementations can change unexpectedly over time.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^4.0 | ^5.0 | — | — |
psr/http-client Version ^1.0 | — | — |
guzzlehttp/guzzle Version ^6.0 | ^7.0 | — | — |
amphp/websocket-client Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.