The repository is backed by an organization and includes tests, a license, and security tooling. Workflow checks leave all actions unpinned and flag a high-confidence bot-condition issue.
58%
Total Score
75
100
88
75
This package has only one release, published over two years ago, with no releases in the last 12 months. That limits evidence of ongoing compatibility and maintenance.
There were no commits and no active maintainers in the last three months. This conflicts somewhat with the recent repository push but still leaves current development momentum uncertain.
The repository has no security policy, which leaves vulnerability-reporting and response expectations undocumented.
Version 0.1.0 is an early major version, so API stability and maturity are less established than for a mature stable release.
All eight workflow action references are unpinned, and the audit found a high-confidence bot-condition issue in a workflow with top-level write permissions. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.