A single maintainer makes continuity more dependent on one person, despite a second recent contributor. Workflow references are all unpinned, though the repository has active security scanning, a security policy, and no high-confidence workflow risks.
82%
Total Score
63
94
100
The name resembles StackExchange.Redis and explicitly identifies that project in its README, which can confuse consumers even though the lower artifact overlap and extension description indicate a related library rather than a direct copy.
The repository is owned by an individual rather than an organization, so the concentrated contributor activity is not offset by clear organizational handoff capacity.
Two contributors were active recently, but the leading contributor made about 84% of the commits. This leaves maintenance continuity concentrated in one person.
The repository has only 8 open issues and 1 open pull request, but there was no issue or pull-request activity in the last month. This is a minor maintenance concern rather than evidence of abandonment because recent commits and releases are present.
All three workflows were analyzed with no untrusted checkout, script injection, or high-confidence severe findings. However, all 10 action references are unpinned, and the audit identified trusted publishing as a lower-severity workflow concern.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-374560 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. StackExchange.Redis.Extensions.Core is vulnerable to Code Injection in versions 10.1.0 - 13.0.0. | 10.1.0 - 13.0.0 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
stackexchange.redis Version [2.12.14, 4.0.0) | — | — |
system.runtime.compilerservices.unsafe Version [6.1.2, ) | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.