The small dependency set and MIT licensing keep adoption straightforward. Organization ownership and a recent release provide continuity, but maintenance is concentrated in one contributor and workflow references are not pinned.
65%
Total Score
83
100
67
All 2 commits in the last 3 months came from one contributor, concentrating recent maintenance knowledge despite the repository being owned by an organization.
The repository has no security policy, leaving vulnerability reporting and response expectations less transparent.
All 20 analyzed action references are unpinned, and the audit found high-confidence template-injection patterns plus a medium-confidence archived action. The template findings are in a release workflow without an observed untrusted checkout or script-injection sink, so they remain hygiene concerns rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
complex-heart/domain-model Version ^5.0.0 || ^6.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.