The source repository has tests, a matching README mention, a license, and a GitHub release. Its single release and nine months without commits leave maintenance capacity unproven; workflow references are all unpinned and one high-confidence template-injection finding needs review.
57%
Total Score
50
92
50
This is the package's only release, published about 10 months ago, so there is little release history to demonstrate sustained maintenance.
The repository recorded zero commits and zero active maintainers in the past three months, despite the latest push being about nine months ago; this weakens evidence of ongoing maintenance.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in a package that performs URL signing and optional source encryption.
All 12 analyzed action references are unpinned, and the audit found a high-confidence template-injection issue in update-changelog.yml. The workflows were fully analyzed and have no untrusted checkout or script-injection findings, so this is a hygiene and review concern rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
thecodingmachine/safe Version ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.