A single contributor made the last two commits, and both workflows grant top-level write access. The repository has tests, security scanning, pinned actions, and a recent release, which supports continued maintenance.
78%
Total Score
70
100
100
83
Only one registry account can publish releases. That is a real resilience concern for this individually owned project, though the repository shows recent activity from the same maintainer.
The repository is owned by an individual rather than an organization, so the single-maintainer and concentrated-contributor risks are not buffered by visible organizational backing.
One contributor made all two commits in the last three months, concentrating maintenance entirely in one person. The non-archived repository and recent release partly compensate, but do not remove the continuity risk.
No repository security policy was found. For a small API client this is a transparency gap, but it is not severe enough to outweigh the active source and security tooling.
Both workflows grant top-level write permissions, which is broader than necessary, but the audit found no untrusted checkouts, script injection, or other findings, and all six action references are pinned. The permissions are a mild hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.