Regular releases and three active contributors support continued maintenance. Clear licensing, types, provenance, tests, and documentation improve adoption; workflow findings are limited to CI hygiene rather than unsafe triggers.
84%
Total Score
75
100
95
67
100
One contributor made about 65% of the 17 recent commits, but two other contributors remain active. The concentration is a mild continuity concern rather than a severe single-person dependency.
No repository security policy was found, leaving vulnerability-reporting guidance less transparent for consumers.
Version 0.126.2 is not a prerelease, although it remains below 1.0 and 60% of recent versions are prereleases. This is a modest stability caveat, not a major adoption barrier.
All four workflows were analyzed with no untrusted checkout or script-injection findings, and three use read-only permissions. However, all 15 action references are unpinned, with a high-confidence archived action, an ad hoc package install, and trusted publishing identified; these are workflow hygiene concerns rather than evidence of unsafe triggers.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10768 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. slate is vulnerable to Prototype Pollution in versions 0.111.0 - 0.124.0. | 0.111.0 - 0.124.0 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.