The mirror has active automated releases, tests, and a changelog, with organization backing. One maintainer owns all five recent commits, while broad workflow write permissions and template-injection findings reduce confidence in its automation hygiene.
68%
Total Score
83
100
94
75
One contributor made all five recent commits, creating a genuine continuity risk. Organization ownership provides some ability to hand off maintenance, but no second active contributor is evidenced.
Composer is used for builds, but no repository security-scanning tool was detected. For an automated binary mirror, this is a modest transparency and hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving reporting and response expectations undocumented for a package that distributes extension source and binaries.
All four workflows were analyzed and all 12 action references are pinned, with no untrusted checkouts or script-injection findings. However, three workflows grant top-level write permissions and the build workflow has high- and medium-confidence template-injection findings; without an untrusted trigger these are workflow-hygiene concerns, not a severe standalone risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.