The package is clearly licensed, documented, tested in its repository, and not deprecated or archived. Maintenance has stalled since the last release, and the workflows contain high-confidence bot-condition and unpinned-image findings.
58%
Total Score
75
100
94
50
All four workflows were analyzed, but all eight action references are unpinned. High-confidence findings also flag spoofable bot conditions and an unpinned container image, creating meaningful workflow supply-chain hygiene concerns.
Only two releases exist, and none were published in the last 12 months; the latest release was about three years ago, indicating weak release maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the concern raised by the old latest release.
There are no open issues and one open pull request, but no issues or pull requests were merged in the last month, offering little evidence of active support.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented; this is a transparency gap for a package making network requests.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.