Clear licensing, a small dependency set, and release notes make the package easy to evaluate. Maintenance is concentrated in one contributor, while workflow credentials are broadly inherited and all six actions are unpinned.
76%
Total Score
83
100
94
75
All 29 recent commits came from one contributor, so maintenance depends heavily on a single person. Organizational ownership provides some handoff capacity, but no second active contributor is evidenced here.
The project uses Composer for builds, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
No security policy was found in the repository, leaving vulnerability reporting guidance unspecified.
All 3 workflows were analyzed with no untrusted checkouts or script-injection findings, but all 6 action references are unpinned and two high-confidence medium-severity findings show secrets inherited by reusable workflows. These are meaningful workflow hygiene and credential-scope concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
innmind/immutable Version ~6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.