Its workflows use broad write access and unpinned actions, with high-confidence template-injection findings. No security policy is published, although the package is licensed and includes tests and release notes.
61%
Total Score
75
88
67
This release is the package's first and was published 0 days ago, so there is no track record for stability or sustained maintenance yet.
All 52 recent commits came from one contributor, leaving maintenance dependent on a single person; the repository owner is a user account rather than an organization.
The linked repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Both workflows grant top-level write permissions, all 5 action references are unpinned, and high-confidence template-injection findings were reported in both workflows. No dangerous trigger or untrusted checkout was observed, so this is a workflow-hygiene caution rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.