The release is licensed, documented, and actively updated, with a stable 2.2.0 line. Keep ownership and workflow credentials under review because recent work is concentrated in one contributor and all actions are unpinned.
68%
Total Score
83
100
94
50
All 12 recent commits came from one contributor. Organization backing provides some handoff capacity, but no second active contributor is shown to reduce the immediate concentration risk.
The repository uses Make and Composer, providing build structure, but no security scanning tools were detected.
No security policy was found, leaving vulnerability reporting and response expectations undocumented.
All six analyzed action references are unpinned, and all three workflows inherit secrets into reusable workflows; one workflow also has top-level write permissions. No untrusted checkout or script-injection path was found, which limits the severity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
innmind/io Version ~4.2 | — | — |
innmind/time Version ~1.0 | — | — |
innmind/signals Version ~5.2 | — | — |
innmind/immutable Version ~6.0 | — | — |
innmind/operating-system Version ~7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.