The repository is organized, licensed, and backed by an organization, with tests and release notes available. GitHub Actions use read-only permissions but all 16 action references are unpinned, leaving a meaningful hygiene gap.
68%
Total Score
100
83
75
The package was published today and has only one release, so there is no demonstrated maintenance cadence or history yet.
The repository has no published security policy, which weakens its vulnerability-reporting and response transparency.
This is the initial v0.1.0 release and is not a stable major version, which increases compatibility uncertainty for adopters.
Both workflows were analyzed and use read-only permissions with no untrusted checkouts, script injection, or audit findings. However, all 16 action references are unpinned, leaving a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
guzzlehttp/psr7 Version ^2.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.