The SDK has clear documentation, tests, release notes, and a permissive license. The repository is young and recent work is concentrated in one contributor, while workflow references are not pinned and one workflow grants broad write access.
80%
Total Score
67
100
100
75
All recent commits came from one contributor, creating concentration risk; organization ownership provides some ability to hand maintenance to others.
There was one commit in the past three months, so maintenance is present but currently light for a young project.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear for an API client.
Both workflows were fully audited with no reported findings or untrusted checkout sinks, but all 7 action references are unpinned and one release workflow has top-level write access, creating moderate workflow hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.