The two-person team is active, though most recent work comes from one contributor. The repository has no security policy, and its workflows use broad write permissions with all four actions unpinned; documented release notes, licensing, and Dependabot partly offset these hygiene concerns.
78%
Total Score
83
100
93
50
One contributor made 24 of 26 recent commits, creating concentration risk, although a second contributor remains active and the repository is organization-owned.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented.
Version 0.4.0 is not yet at a stable major version, so API changes remain more likely despite the absence of prerelease labeling.
Both workflows grant top-level write permissions and all four analyzed action references are unpinned. The audit found no untrusted checkout, script injection, or high-severity issue, so this is workflow hygiene risk rather than a severe finding.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
microsoft/kiota-http-guzzle Version ^2.0 | — | — |
microsoft/kiota-abstractions Version ^2.0 | — | — |
microsoft/kiota-serialization-form Version ^2.0 | — | — |
microsoft/kiota-serialization-json Version ^2.0 | — | — |
microsoft/kiota-serialization-text Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.