Four maintainers made 44 commits in three months, and the organization-backed repository is current. The MIT license, tests, and security scanning support continued use.
70%
Total Score
100
100
89
67
The repository name matches the package, but the README does not mention the package name, leaving a small transparency concern about the exact package relationship.
The repository has only 1 star and no forks or watchers, indicating limited external adoption; this is supporting caution, not decisive evidence because current activity is strong.
No repository security policy was found, leaving vulnerability-reporting expectations less clear for consumers.
All nine action references are unpinned, and the audit found one high-confidence template-injection issue in the quality-assurance workflow. No untrusted checkout or script-injection path was detected, so this is a meaningful hygiene concern rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.