The repository has no security policy, and all six GitHub Actions references are unpinned. Two workflows also inherit secrets, while organization ownership and recent releases provide useful continuity.
67%
Total Score
67
100
50
One contributor made 100% of the four recent commits. Organization backing partly reduces handoff risk, but the observed contributor base remains concentrated.
The repository recorded four commits in the last three months, showing current activity. However, all four were made by one active maintainer, limiting demonstrated maintenance breadth.
The repository has no security policy. This is a transparency gap for reporting and handling vulnerabilities, although it does not by itself show that the package is unsafe.
All three workflows were analyzed, with no untrusted checkouts or script injection, but all six action references are unpinned and two high-confidence medium-severity findings show secrets being inherited by reusable workflows. These are meaningful workflow-hygiene and credential-scope concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
innmind/url Version ~5.0 | — | — |
innmind/immutable Version ~6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.