The package includes a license, tests in the repository, release notes, and security tooling. Its release and commit activity has stopped, while the linked repository neither matches the package name nor mentions it; workflow permissions and bot checks add supply-chain hygiene concerns.
48%
Total Score
75
100
79
100
The repository name does not match the package and its README does not mention the package, so the source may not actually belong to this release.
The package has 29 releases over roughly four years, but none in the last 12 months, indicating a substantial maintenance pause despite its earlier regular cadence.
The repository recorded zero commits and zero active maintainers in the last three months, weakening evidence of ongoing maintenance.
All four workflows were analyzed, but all nine action references are unpinned, three workflows grant top-level write permissions, and a high-confidence bot-conditions finding concerns auto-merge logic. These are meaningful workflow hygiene and supply-chain risks even without an untrusted checkout or script-injection sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.4.5 | — | — |
microsoft/kiota-abstractions Version ^1.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.