The package includes tests in its repository, a changelog, a clear MIT license, and minimal runtime dependencies. GitHub Actions need cleanup because all 10 action references are unpinned and high-confidence template-injection patterns were reported, although no untrusted trigger or checkout was found.
78%
Total Score
100
100
93
67
Composer build tooling is present, supporting a reproducible project workflow, but no security-scanning tool was detected, leaving a minor process gap.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in a package that integrates with GitLab APIs.
All 10 analyzed action references are unpinned, and the audit reports high-confidence template-injection patterns plus an unsound condition. However, there are no pull_request_target or workflow_run triggers and no untrusted checkouts or script-injection findings, so this is workflow hygiene risk rather than a standalone severe dependency risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.