University of Colorado Boulder custom entities
70%
Total Score
caution
Active releases and organizational backing offset a license mismatch and weak GitHub Actions pinning.
The artifact declares MIT but its LICENSE file was detected as GPL-2.0, creating a material licensing ambiguity despite a license file being present.
The repository name does not match the package name and its README does not mention the package, so the linkage is less transparent even though the repository content appears related to custom entities.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, which makes vulnerability reporting and response expectations less clear.
All five workflows were analyzed without untrusted checkouts or script injection, but all five uses are unpinned and one high-confidence medium-severity finding shows secrets inherited by a reusable workflow. Missing top-level permissions blocks are acceptable on their own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.