The package includes a clear README, tests, matching Apache-2.0 licensing, and no install-time scripts. Ongoing repository activity and organizational ownership offset concentrated contributions, while workflow pinning and security-policy gaps remain.
86%
Total Score
83
94
67
Two contributors were active, but one made 11 of 13 commits, leaving maintenance notably concentrated despite organizational backing.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest verification gap.
No repository security policy was detected, reducing transparency around vulnerability reporting and response.
All 5 workflows were analyzed with no audit findings and the pull_request_target workflow has no untrusted checkout or script-injection sink. However, all 12 action references are unpinned, a reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.