The project has recent commits, a fresh release, tests in its repository, documentation, and a security policy. The release is a prerelease, all 11 workflow actions are unpinned, and recent commits come from one contributor, so maintenance and build reproducibility deserve attention.
78%
Total Score
88
100
89
83
All 17 commits in the last three months came from one contributor, concentrating recent maintenance responsibility. Organization backing provides some handoff capacity, but no second active contributor is shown.
The repository uses Composer, but no security-scanning tool was detected. The security policy and other repository controls provide some transparency, so this is a modest hygiene gap rather than a major health concern.
Version 6.1.0-rc1 is a prerelease, so its API and behavior may still change before the stable release. The package is on an established major version and only 25% of recent releases were prereleases, limiting the concern.
Both workflows were analyzed successfully and no dangerous triggers, untrusted checkouts, script injections, or audit findings were reported. However, all 11 action references are unpinned, weakening build reproducibility; the absence of top-level permissions is not a concern by itself.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.