The package includes a README, repository tests, release notes, and a current source repository. Workflow auditing found no dangerous findings, but all 13 action references are unpinned and the repository has no security policy.
62%
Total Score
50
100
92
50
The package has existed since March 2021 and released version 0.2.4 in February 2026, but only one release occurred in the last 12 months and the median interval is about 260 days. This indicates slow rather than absent maintenance.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, which raises a maintenance and abandonment concern. This is partly offset by the recent 0.2.4 release and repository push activity.
The linked repository has no security policy, reducing transparency about vulnerability reporting and response. The package is otherwise actively published and its source repository remains available, so this is a hygiene concern rather than a severe risk.
All 3 workflows were analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 13 action references are unpinned, leaving avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.