The project is young and still pre-1.0, so compatibility expectations are limited. Its workflows have reusable-workflow secret inheritance and all five action references are unpinned, adding maintenance and build-integrity concerns.
68%
Total Score
90
100
94
83
All 11 recent commits came from one contributor, leaving maintenance dependent on a single active developer; organization backing partly reduces but does not remove this concern.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
Version 0.3.0 is not a stable major release, so consumers should expect possible compatibility changes despite the absence of prerelease versions.
The audit found high-confidence medium-severity secrets-inherit findings in two reusable workflows, and all five analyzed action references are unpinned. No untrusted checkout, script injection, top-level write permissions, or incomplete audit was reported.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sylius/sylius Version ^2.1 | — | — |
league/commonmark Version ^2.8 | — | — |
symfony/type-info Version ~7.3.0 | — | — |
symfony/ai-platform Version ^0.8 | — | — |
api-platform/symfony Version ^4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.