Regular releases, a large README, tests, and release notes provide useful maintenance evidence. The organization-backed repository is correctly linked, but all three workflow actions are unpinned and no security policy is published.
69%
Total Score
75
100
94
75
There were no commits and no active maintainers during the last three months, a meaningful maintenance concern despite the recent release and push activity.
Three pull requests were opened in the last month, showing some activity, but none were merged and no issues were closed, so this only partly offsets the absent recent commits.
The repository has no stars, forks, or watchers, which provides little external validation; however, the package is only about 10 months old and popularity is supporting evidence rather than a verdict.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear for a client library that handles API access.
The single workflow was fully analyzed with no injection or high-confidence audit findings, but all three action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.