The package is well documented, tested, licensed, and actively developed by two contributors in an organization-owned project. Its dependency list is moderate and installation has no lifecycle scripts, but it lacks a security policy.
76%
Total Score
100
100
88
67
The package is only 5 days old, despite 7 releases in that period; this shows active iteration but provides little evidence of long-term maturity.
No repository security policy was found, leaving reporting and response expectations undocumented.
Version 0.5.0.0 is not a stable major release, so compatibility expectations are lower even though it is not marked as a prerelease.
The single workflow was fully analyzed with no reported audit findings or untrusted execution sinks. However, all 5 action references are unpinned and the workflow grants top-level write permissions, creating a moderate reproducibility and token-scope hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^7.4|^8.0 | — | — |
react/event-loop Version ^1.5 | — | — |
react/child-process Version ^0.6.6 | — | — |
bluetree-service/data Version ^0.5 | — | — |
bluetree-service/symfony-console-style Version ^0.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.