University of Colorado Boulder base theme
84%
Total Score
100
89
80
A substantive README and changelog are present, and the repository uses GitHub Releases, but neither the artifact nor repository contains tests. For a Drupal theme this is a maintenance and regression-testing gap, though linting and active development provide some compensation.
Composer is used as a build tool, but no security scanning tools are configured. The missing security automation is a hygiene gap, although the repository has other CI workflows and no dangerous workflow patterns were detected.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
All five workflows lack top-level token permissions declarations. Although none declares top-level write access, explicit least-privilege permissions would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.