The package is licensed, well documented, and has no install-time scripts. Its small contributor base is balanced by organization backing, security tooling, and a release with documented changes.
86%
Total Score
100
94
100
The package has released only four times since June 2023, with roughly one release in the last 12 months and a median interval of about 11 months. Recent repository activity and the latest release partly compensate for the slow cadence.
All eight workflows use read-only permissions and the audit found no dangerous triggers, untrusted checkouts, script injection, or other findings. However, all 10 analyzed action references are unpinned, leaving a reproducibility and action-substitution hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/http Version ^1.2 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
psr/http-server-handler Version ^1.0 | — | — |
yiisoft/network-utilities Version ^1.1 | — | — |
psr/http-server-middleware Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.