Recent releases and substantial test coverage support continued maintenance. The organization has two active contributors, while workflow references are not pinned and no security policy is provided.
84%
Total Score
100
100
75
The repository has no SECURITY.md policy. This is a transparency and vulnerability-reporting gap, though it is partly offset by the project's active development and testing.
All 7 analyzed action references are unpinned, creating reproducibility and action-substitution risk; one workflow also grants top-level write permissions. The audit found no untrusted checkout or script-injection paths, limiting the impact to caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jms/serializer Version ^3.20 | — | — |
psr/http-client Version ^1.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.