Clear README, tests, changelog, licensing, and no install scripts make adoption straightforward. Workflow pinning and the missing security policy add smaller process concerns.
65%
Total Score
67
92
75
One contributor made all recent commits, creating a concentrated maintenance path; organization backing provides some ability to hand work to others.
Only one commit was recorded in the last three months, which suggests maintenance has slowed despite the repository remaining active.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The package is not yet at a stable major version, so its APIs may change; the release is not marked as a prerelease, which partly offsets that concern.
All three workflows were analyzed with no untrusted checkout or script-injection findings, but 15 of 17 action references are unpinned and one workflow installs a package outside a lockfile.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.8 | — | — |
guzzlehttp/psr7 Version ^1.8 || ^2.0 | — | — |
php-http/httplug Version ^2.2 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.