PHP library for accessing Yahoo Finance data
68%
Total Score
caution
Usable with caveats: recent maintenance is positive, but all workflow actions are unpinned and one contributor did the recent work.
All recent commit activity came from one contributor, leaving maintenance dependent on a single active person; the repository owner is an individual rather than an organization that could more readily hand work off.
The repository had one commit in the last three months, showing recent activity but a very thin maintenance cadence for a mature package.
The repository has no published security policy, reducing transparency about how vulnerability reports should be handled.
The single workflow was fully analyzed without dangerous triggers, untrusted checkouts, or audit findings, but all 13 action references are unpinned. That weakens build reproducibility and supply-chain control without making the release unfit on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^2|^3 | — | — |
guzzlehttp/guzzle Version ^7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.