It includes a substantial README, exact-version release notes, and a permissive MIT license. The single-contributor repository and unpinned workflow actions leave some operational risk.
81%
Total Score
75
94
83
The repository is owned by an individual rather than an organization, so the one-person publishing and commit profile is not buffered by visible organizational backing.
All 15 recent commits came from one contributor, so maintenance depends heavily on a single person and has a meaningful continuity risk.
No build or security-scanning tools were detected in the repository. This is a transparency and assurance gap, though active releases and repository activity partly compensate for it.
The repository has no security policy, leaving vulnerability-reporting expectations unclear; this is a moderate transparency gap rather than evidence of abandonment.
Both workflows were analyzed without failed files or audit findings, and one scopes permissions at job level. However, both action references are unpinned and one workflow grants top-level write access, creating workflow hygiene and token-scope concerns.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-918851 SharpYaml is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 2.1.4 and 3.0.0 - 3.3.0. | 0.0.1 - 2.1.43.0.0 - 3.3.0 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
system.collections.immutable Version [9.0.0, ) | — | — |
system.buffers Version [4.6.1, ) | — | — |
system.text.json Version [10.0.3, ) | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.