The package is documented, tested, MIT-licensed, and backed by a non-archived organization repository. Its six workflow actions are unpinned, and the registry has not published a release since March 2021 despite the repository being pushed more recently.
65%
Total Score
75
93
75
Only four releases exist, with no release in the last 12 months and the latest published in March 2021. This is a meaningful maintenance concern, though the linked repository was pushed more recently.
There were no commits and no active maintainers in the last three months. The absence of recent development lowers confidence in ongoing maintenance, even though the repository is not archived.
The repository has no security policy. This is a modest transparency gap for a library that handles API tokens, but it is not evidence of abandonment by itself.
The single workflow was fully analyzed with no detected injection or high-severity findings, but all six action references are unpinned. That leaves avoidable update and supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.1 | — | — |
beberlei/assert Version ^3.0 | — | — |
myclabs/php-enum Version ^1.6 | — | — |
php-http/httplug Version ^2.2 | — | — |
php-http/message Version ^1.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.