The project is young but releasing actively, with tests, a changelog, a license, and a security policy. GitHub Actions use read-only permissions but all four action references are unpinned, so supply-chain hygiene remains imperfect.
68%
Total Score
67
100
94
88
The package is only 44 days old but already has nine releases, with the latest published 28 days after the first. This shows active early development, although the short history limits evidence of long-term maintenance.
One contributor made all 14 commits in the last three months, giving the project a 100% top-contributor share. Organization backing partly offsets the risk, but the observed maintenance base is still concentrated.
The repository had 14 commits in the last three months, indicating ongoing work. However, those commits came from only one active maintainer, so continuity depends heavily on that person.
All three workflows were analyzed successfully, all have read-only permissions, and no dangerous triggers, untrusted checkouts, script injection, or audit findings were detected. All four action references are unpinned, which leaves update behavior less reproducible.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.7 | — | — |
psr/http-client Version ^1.0 | — | — |
firebase/php-jwt Version ^7.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.