The package is clearly identified, licensed, tested in its repository, and has no install-time scripts. Workflow permissions and fully unpinned actions add avoidable maintenance and supply-chain hygiene concerns.
65%
Total Score
83
100
88
75
The package has five releases over about 653 days, but only one release in the last 12 months; this indicates a modest and slowing release cadence for a 0.x package.
There were no commits and no active maintainers in the last three months, which is a maintenance concern, although the repository was pushed recently and pull requests are being merged.
No repository security policy was found, reducing transparency for reporting vulnerabilities in a package that consumes vulnerability-feed data.
Version 0.2.0 is a stable release rather than a prerelease, but the package remains below 1.0, so its API may still change materially.
All six workflows were analyzed, but all 16 action references are unpinned and two workflows grant top-level write access. The high-severity cache-poisoning finding has low confidence and is hygiene-level, while high-confidence secrets inheritance warrants caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/semver Version ^3.4 | — | — |
guzzlehttp/guzzle Version ^7.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.