Directed workflow engine with status-based transitions, automatic data accumulation, and builder API
68%
Total Score
caution
Usable with caveats: active releases are offset by one-person maintenance and workflow security gaps.
One contributor made all five commits in the last three months, creating a meaningful continuity risk. Organization backing provides some handoff capacity but does not replace a second active contributor.
Five commits in three months show ongoing work, but the activity is modest and concentrated in one active maintainer.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
All seven action references are unpinned, and the audit found a high-confidence template-injection issue in the release workflow. There is no untrusted checkout or pull-request-target trigger, so this is a hygiene and workflow-risk concern rather than a standalone severe verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jardissupport/contracts Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.