SDK For vShip API
68%
Total Score
67
100
100
75
All recent commits came from 1 contributor, creating a fragile maintenance path. Organization ownership provides some backing, but no second active contributor is shown.
Only 1 commit was recorded in the last 3 months, indicating sparse recent development activity despite the current release.
No repository security policy was found, leaving vulnerability-reporting expectations unclear for an SDK that handles API integrations.
The single workflow was fully analyzed with no untrusted checkouts or script injection, but all 8 action references are unpinned and one high-confidence finding identifies an archived action. The lack of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cuyz/valinor Version ^2.5 | — | — |
guzzlehttp/guzzle Version ^7.5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.