Clear licensing, documentation, tests, and frequent releases support adoption. Limit workflow trust and pin a reviewed commit because the automation has broad unpinned action use and several high-confidence findings.
72%
Total Score
83
100
100
50
The package defines a post-install command, which adds install-time execution and therefore some supply-chain exposure, although this signal does not show that the script is unsafe.
One contributor made about 92% of recent commits, leaving a concentrated bus factor. Organization backing and a second active contributor partly compensate, but succession risk remains.
The repository has no SECURITY.md or other detected security policy, reducing transparency for reporting vulnerabilities.
All 25 analyzed action references are unpinned, and three high-confidence template-injection findings were reported in workflow files. There are no untrusted checkouts or script-injection findings, so this is a meaningful hygiene concern rather than a standalone severe verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/event-dispatcher Version ^1.0 | — | — |
gacela-project/container Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.