MIT licensing and a clear security policy support straightforward adoption. All three workflow actions are unpinned, a minor supply-chain hygiene concern.
89%
Total Score
100
100
83
Both workflows were fully analyzed with no untrusted checkouts, script injection, or audit findings. However, all 3 referenced actions are unpinned, creating a minor reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.9 || ^2.0 || ^3.0 | — | — |
phpunit/phpunit Version ^9.6.17 || ^10.0 || ^11.0 || ^12.0 | — | — |
php-http/message Version ^1.0 || ^2.0 | — | — |
th3n3rd/cartesian-product Version ^0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.