The project has clear licensing, repository tests, release notes for this version, and organization backing. Workflow hygiene is generally sound, though the low-confidence cache warning and missing security policy leave modest transparency concerns.
72%
Total Score
88
94
67
There were no commits from active maintainers in the last three months. Recent releases and merged pull requests soften the concern, but the lack of direct commit activity still weakens evidence of sustained maintenance.
The repository uses Composer, but no security scanning tools were detected. For this small shell-script package this is a modest transparency gap rather than a severe dependency risk.
No security policy is present in the repository, leaving vulnerability-reporting expectations unclear.
The single workflow was fully analyzed, uses read-only permissions, and has no untrusted checkout or script-injection findings. The low-confidence cache-poisoning warning is hygiene at most under the audit rules, while all four action references are unpinned.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.