The package is licensed, documented, and has no install-time scripts. Workflow hygiene is weaker, with unpinned actions and an archived action, while maintenance depends heavily on one contributor.
72%
Total Score
75
100
50
Two contributors are active, but one contributor made 6 of 7 recent commits, leaving maintenance materially concentrated.
The repository has no security policy or security-scanning tooling shown, reducing transparency for reporting and handling security issues.
All 5 analyzed action references are unpinned, and the audit found a high-severity but low-confidence cache-poisoning pattern, a high-confidence archived action, and ad hoc package installation. There are no untrusted checkouts or script-injection findings, which limits the risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.