The package has clear licensing, release notes, documentation, and organization backing. Recent repository activity has stopped, while workflow checks leave all six actions unpinned and flag high-confidence template-injection patterns.
68%
Total Score
75
100
75
The repository had zero commits and zero active maintainers in the last three months, a concrete sign that maintenance may be slowing or paused.
There were nine open issues but no new or closed issues and no merged pull requests in the last month, leaving current issue maintenance unclear and adding abandonment concern.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in a package intended for application workflows.
All six action references are unpinned, and two workflows have high-confidence template-injection findings; the audit also flags an ad hoc package installation. The pull_request_target workflow has no untrusted checkout or script-injection finding, so these are workflow-hygiene concerns rather than severe evidence on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
humanmade/workflows Version ~0.4.10 | — | — |
yoast/duplicate-post Version ~4.6.0 | — | — |
humanmade/publication-checklist Version ~0.4.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.