The package includes a README, repository tests, and a matching MIT license. Workflow hygiene is weak: all four actions are unpinned and one uses an archived action.
58%
Total Score
50
80
50
The package has eight releases, but none in the last 12 months; the latest release was published over one year ago. This indicates materially slowed maintenance despite a previously active release burst.
The repository recorded no commits and no active maintainers in the last three months. The repository is not archived, but this recent inactivity raises abandonment risk.
Composer build tooling is present, but no security scanning tools were detected. This is a modest process gap, partly offset by the repository's working test structure.
The repository has no security policy. For a small library this is a transparency gap, though it is less serious than the observed maintenance slowdown.
All four analyzed action references are unpinned, and one workflow uses an archived action with high-confidence medium severity. The audit found no untrusted checkout or script-injection paths, which limits the risk to workflow hygiene rather than a severe exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.