Repository tests, licensing, and release notes provide useful confidence for consumers. Recent work is concentrated in one contributor, while unpinned actions and no security policy leave modest maintenance and workflow-hygiene concerns.
79%
Total Score
50
100
100
75
All recent commits came from one contributor, giving the project a low recent contributor diversity. The long project history and active repository reduce, but do not remove, this concentration risk.
Only one commit was recorded in the last 3 months, indicating limited recent development activity. The recent release history partly offsets this, but the narrow activity is still a maintenance concern.
No security policy was found in the repository, leaving disclosure and response expectations unclear. This is a modest transparency gap rather than evidence of abandonment.
Both workflows were analyzed without dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 4 action references are unpinned, which creates a workflow reproducibility and dependency-hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/ca-bundle Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.