A security policy and automated security scanning add useful safeguards. The workflows use unpinned actions, broad inherited secrets, and write permissions, so release automation deserves review before adoption.
78%
Total Score
83
94
100
The repository is owned by an individual rather than an organization, so the concentrated contributor activity is relevant; the presence of five active contributors partly offsets that risk.
The assessed version is a beta and every recent release is a prerelease, so compatibility may still change even though development is active.
All four workflows were analyzed without failures and have no untrusted checkout or script-injection findings. However, all four action references are unpinned, two workflows grant top-level write permissions, and two high-confidence medium-severity findings pass inherited secrets to reusable workflows.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version ^2.0.0-rc | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.