The package was released today, so there is no track record yet; its organization-backed repository has not accumulated popularity or activity evidence. Strong tests, a clear MIT license, and a clean workflow audit help, but all 10 workflow actions are unpinned and no security scanning or policy is present.
67%
Total Score
100
83
75
This is the package's first release, published today, so there is no release cadence or history demonstrating sustained maintenance. That is a meaningful maturity concern for a dependency.
The repository has zero stars, forks, and watchers. For a package released today this is not surprising, but it offers no supporting evidence of adoption or review.
Composer build tooling is present, but no security scanning tools were detected. That leaves a useful quality-control gap for a package handling request-signing code.
No repository security policy was found. This is a transparency and reporting gap, though it is not severe enough on its own to make the package unfit.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 10 action references are unpinned, leaving the build exposed to moving action code.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.