It includes clear documentation, repository tests, a license, a security policy, and a small runtime dependency set. Pin a later release after the project has established a longer maintenance record and tighten its unpinned workflow actions.
62%
Total Score
83
100
81
88
The package is less than a day old with four releases and a median interval of under 9 hours, so there is too little history to establish dependable maintenance or release quality.
There were no commits and no active maintainers in the last 3 months. Because the project is less than a day old, this mainly reflects insufficient history rather than proven abandonment, but it prevents confidence in sustained maintenance.
The repository has no stars, forks, or watchers. This is weak supporting evidence, but the package is less than a day old, so the absence is not decisive.
Composer build tooling is present, but no security scanning tools were detected. The repository's security policy partly compensates for this hygiene gap.
The workflow was fully analyzed with read-only permissions and no dangerous audit findings, but all 14 action references are unpinned, leaving avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
php-http/discovery Version ^1.20 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.