The MIT license, focused dependency set, and repository tests make adoption straightforward. The project is not archived and this release has notes, but its limited history leaves maintenance capacity unproven.
63%
Total Score
75
100
92
50
This is the only release after about seven months of package age, so there is little evidence of sustained release maintenance.
There were no commits and no active maintainers in the three months measured, indicating little demonstrated maintenance activity after the initial release.
The repository has no security policy and no security scanning tools. This is a transparency and hygiene gap, though it is not evidence that the package is unsafe.
The single workflow was fully analyzed with no untrusted trigger or script-injection sink, but both high-confidence findings concern unpinned container images and all five action references are unpinned.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.