The repository includes tests, a changelog, and a clear README. Workflow dependencies are not pinned and no security scanning is present; keep the dependency version fixed while the project matures.
76%
Total Score
100
100
79
75
This is the package's first release, published today, so there is no release track record yet. The linked repository and release notes provide some transparency, but maintenance over time remains unproven.
Composer build tooling is present, but no security scanning tools were detected. That is a modest transparency and maintenance gap for a newly published SDK.
The release is not a prerelease, but it is still version 0.1.0 rather than a stable major release. That indicates an early project stage rather than a severe dependency risk.
The single workflow was fully analyzed, uses read-only permissions, and has no dangerous triggers or audit findings. All six referenced actions are unpinned, leaving the workflow exposed to upstream reference changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.13 | — | — |
psr/simple-cache Version ^1 || ^2 || ^3 | — | — |
guzzlehttp/guzzle Version ^7.15.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.