The repository is active, has tests, and this release includes specific notes about its packaging fix. Its main weaknesses are the package's same-day release history and workflows that leave all 16 actions unpinned, with one workflow granting broad write access.
68%
Total Score
100
86
67
The package is brand new, with only two releases published on the same day, so there is little evidence of long-term maintenance or release discipline.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented; this is a modest transparency gap for a library.
Version v0.7.1 is not a stable major release, which is reasonable for an early project but signals that its API and behavior may still change.
All 16 analyzed action references are unpinned, and one workflow uses top-level write permissions. The audit also found high-severity but low-confidence cache warnings and several high-confidence ad hoc package installs, so workflow hygiene is a real caution rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.