This is a healthy, actively maintained release with strong transparency and organizational backing. It has a clear MIT license, a substantial README and changelog, a matching source repository, regular releases over the past 237 days, recent repository activity, and no deprecation or archival indicators. The main concerns are the absence of tests in both the package and repository, no detected security-scanning tooling, and several workflows declaring top-level write permissions; these are meaningful hygiene gaps but are partly outweighed by the active Shopify organization ownership, current development, security policy, and otherwise coherent package structure.
84%
Total Score
100
100
89
80
Two workflows use pull_request_target and one uses workflow_run, which warrants review of privileged CI paths. However, no untrusted checkouts or script-injection patterns were detected, limiting the health impact.
The package has a substantial README and changelog, but neither the artifact nor repository contains tests. For a security-sensitive application library, the lack of visible tests is a maintenance and regression-risk concern.
Composer build tooling is present, but no security-scanning tools were detected. For a package handling authentication and tokens, this is a security-process hygiene gap, though it does not by itself establish abandonment or unsafe code.
All four workflows declare top-level permissions, but three grant top-level write permissions and only one is read-only. Explicit permissions are better than omission, yet broad write access remains a CI hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^7.0 | — | — |
guzzlehttp/guzzle Version ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.