Tests, release notes, and an Apache-2.0 license provide good consumer and legal clarity. Repository tooling and organization backing help, while the missing security policy and unpinned workflow action add modest process risk.
70%
Total Score
67
94
75
The package has 52 releases over roughly 11 years, but none in the last 12 months. This lowers confidence in current release maintenance, although the linked repository remains active.
All one recent commit came from a single contributor, concentrating short-term maintenance activity. Organization ownership provides some handoff capacity, but does not remove the current concentration.
Only one commit was recorded in the last three months, showing limited recent code activity. Recent merged pull requests and the recent repository push provide some compensating evidence.
No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented.
The single workflow completed auditing without high- or medium-severity findings and has no untrusted checkout or script-injection paths. Its one action is unpinned and the workflow lacks a top-level permissions block, creating modest reproducibility and permission-hygiene concerns.
| Title | Versions | Severity |
|---|---|---|
CVE-2021-30492 zendesk/zendesk_api_client_php is vulnerable to Improper Input Validation in versions 0.0.0 - 2.2.11. | 0.0.0 - 2.2.11 | Low |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
mmucklo/inflect Version 0.3.* | — | — |
guzzlehttp/guzzle Version ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.