The repository has tests, release notes, dependency scanning, and a clear package match. It is still a very young project with only 40 days of history, and the workflow audit failed to inspect three files; no security policy is published.
78%
Total Score
75
100
89
67
The package and repository are owned by the same individual account. This is coherent ownership, but it indicates a limited backing structure rather than organizational support.
The project is only 40 days old with four releases, so it shows early activity but has not yet demonstrated long-term maintenance.
The repository has no stars, forks, or watchers. This is weak supporting evidence for maturity, but popularity alone does not outweigh the package's other signals.
The repository has no published security policy, leaving vulnerability-reporting and response expectations undocumented.
All three workflows were analyzed with no detected findings, read-only or job-scoped permissions, and all eight action references pinned. However, three files failed audit processing, so the clean result is incomplete.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.