It has a clear README, tests, MIT licensing, and an organization-backed repository with recent commits and releases. Keep its GitHub Actions configuration under review because all action references are unpinned and high-confidence template-injection findings were reported.
78%
Total Score
100
94
75
The project uses Make, Composer, and Box for builds, but no security scanning tool was detected. This is a modest transparency and maintenance gap for a deployment tool.
The repository has no security policy. For a deployment tool that can affect remote servers, the missing disclosure and response process is a genuine transparency gap.
All 29 action references are unpinned, and the audit found three high-confidence template-injection findings in build.yaml; the low-confidence cache finding is only hygiene. No untrusted checkout or injection trigger was reported, so this is caution rather than a severe verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.1 | — | — |
symfony/config Version ^7.1 | — | — |
symfony/finder Version ^7.1 | — | — |
symfony/console Version ^7.1 | — | — |
symfony/process Version ^7.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.