The repository has no security policy, and its workflows inherit secrets while all six actions are unpinned. Clear documentation, tests, release notes, and a small dependency set reduce adoption friction.
72%
Total Score
67
100
100
67
One contributor made 100% of the recent commits. Organization backing provides some handoff capacity, but no second active contributor is shown, so the release remains dependent on a narrow active base.
The repository recorded seven commits in the last three months, showing active work rather than abandonment. However, all seven came from one active maintainer, leaving limited observed maintenance redundancy.
The linked repository has no security policy. This is a transparency and response-process gap, although it is not evidence that the package is unsafe.
All three workflows were analyzed without untrusted checkouts or script injection, but all six action references are unpinned and two high-confidence medium-severity findings show secrets being inherited by reusable workflows. These are meaningful workflow hygiene and credential-scope concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
innmind/immutable Version ~6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.