Regular releases, current repository activity, and release notes support dependable maintenance. The automation uses broad app credentials and leaves all 16 actions unpinned, so workflow hygiene needs improvement.
78%
Total Score
100
100
100
50
The repository has no published security policy. This is a transparency gap, though it is outweighed by the active maintenance and Dependabot evidence.
All three workflows were analyzed without failures and have no untrusted checkouts or script-injection findings, but all 16 action references are unpinned and the update workflow has a high-confidence finding that an app token inherits blanket installation permissions. These are meaningful automation-hygiene weaknesses, though no dangerous trigger-and-sink combination was observed.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.