The repository has two active contributors, but one made 94% of recent commits. There is no security policy, while tests, release notes, and scanning support ongoing maintenance.
78%
Total Score
83
100
67
Recent activity is highly concentrated: one contributor made 34 of 36 commits, leaving limited demonstrated redundancy despite a second active contributor.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
All four workflows were analyzed cleanly with no dangerous triggers, untrusted checkouts, or audit findings. However, all 19 action references are unpinned, which weakens build reproducibility and action supply-chain protection.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ray/di Version ^2.18 | — | — |
aura/sql Version ^5.0 || ^6.0 | — | — |
bear/package Version ^1.14 | — | — |
bear/app-meta Version ^1.6 | — | — |
bear/resource Version ^1.32 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.