Clear licensing, a lean runtime dependency profile, and organization ownership support adoption. The repository also uses Composer security scanning and documents this release, but its operational workflow controls need attention.
62%
Total Score
100
100
86
67
This package is less than one day old with only two releases, so there is not yet enough history to demonstrate sustained maintenance or release stability.
No repository security policy was found, leaving reporting and disclosure expectations undocumented.
v0.2.0 is not marked as a prerelease, which is positive, but the package has no established release history to support confidence in long-term stability.
Both workflows were fully analyzed, but all 32 action references are unpinned. The audit also reports repeated high-confidence github-app findings and high-confidence template-injection findings; with no untrusted checkout or dangerous trigger detected, these are workflow hygiene and credential-scope concerns rather than standalone severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.