Organizational backing, a recent release, tests, release notes, and a clear MIT license support continued use. Three of four workflow actions are unpinned, repository commits were absent for three months, and no security policy was found.
72%
Total Score
75
100
94
67
No commits and no active maintainers were observed in the last three months. The recent release and push provide some compensation, but the current development pause still lowers maintenance confidence.
There is one open issue and four open pull requests, with no issues or pull requests merged in the last month; this suggests limited recent interaction but is not evidence of abandonment by itself.
The repository name does not match the package name and its README does not mention the package, so the linkage is less transparent even though the organization and SDK context provide some compensation.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, although it does not by itself show unsafe code.
The sole workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but three of four action references are unpinned and the workflow has no top-level permissions block. The missing block is acceptable on its own; the unpinned references are a modest supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4 | — | — |
guzzlehttp/guzzle Version ^7.9 | — | — |
netresearch/jsonmapper Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.