The project is young but has recent activity from two contributors and organization backing. It includes a clear README, licensing, tests in the repository, and security scanning, though the security policy is absent.
62%
Total Score
100
86
67
The package is only 91 days old and has six releases clustered near its initial publication, so long-term maintenance is not yet demonstrated.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Version 0.4.0 is not a stable major release, which indicates an evolving interface and greater change risk for adopters.
All 34 analyzed action references are unpinned, and four workflows grant top-level write permissions; high-confidence template-injection, broad-token, and inherited-secret findings add workflow hygiene concerns, though no untrusted checkout or script-injection trigger was found.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.