The repository lacks a security policy, and all workflows grant broad write tokens; a high-confidence template-injection finding also needs attention. Recent commits, tests, releases, and pinned actions provide solid maintenance evidence.
78%
Total Score
83
100
100
67
Two contributors are active, but the leading contributor made about 74% of recent commits. The second contributor provides some continuity, so this is a moderate concentration concern rather than a severe one.
No repository security policy was found. This is a transparency gap for reporting vulnerabilities, though it does not by itself show abandonment.
All four workflows grant top-level write permissions, which is broader than necessary, and the audit found one high-confidence template-injection issue in the release workflow. No untrusted checkout or script-injection sink was found, so these remain workflow hygiene concerns rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.