The package is clearly documented, narrowly scoped, licensed, and has no install-time scripts. Recent refreshes and organizational ownership provide continuity, but pin this version until the workflow permissions are tightened.
67%
Total Score
83
100
100
67
All four recent commits came from one contributor, leaving maintenance dependent on a single active person. Organization ownership provides some handoff capacity but does not remove the concentration.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
All workflows were analyzed and action references are pinned, but two high-confidence findings show GitHub app tokens with blanket access to all repositories. The broad permissions are a meaningful supply-chain hygiene concern even though no untrusted checkout or script injection was found.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.