Usable with caveats: this is a newly published package with little track record, but it has a clear README, release notes, repository tests, and active same-day development. Review its GitHub Actions permissions before adopting it in a security-sensitive project.
72%
Total Score
83
100
94
70
One of five workflows uses pull_request_target for Dependabot auto-merge, which warrants review because that trigger can grant elevated workflow context, although no untrusted checkout or script injection was detected.
The package and repository are owned by the same individual, which is coherent for a small personal project, but it also indicates a single-person support base.
The package was first released today and has only two releases, so there is not yet enough history to demonstrate long-term maintenance or compatibility stability.
The repository has no security policy, leaving vulnerability-reporting expectations unclear for consumers of this new package.
Three workflows request top-level write permissions and two omit top-level permissions, indicating broader-than-necessary or unclear CI token access that should be tightened or reviewed.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.