Usable with caveats: it is actively released, licensed, backed by an organization, and has matching source with automated checks. Maintenance is concentrated in one contributor, while the repository lacks a security policy and mostly omits explicit workflow permissions.
72%
Total Score
75
100
100
63
Seven workflows were analyzed and one uses pull_request_target, which warrants care because that trigger can expose elevated workflow context to pull requests. No untrusted checkouts or script-injection patterns were detected.
One contributor made all five recent commits, creating a real continuity risk. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Five commits were made in the last three months, showing current activity, but all activity came from one maintainer.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear for a payment integration.
Six workflows lack top-level permissions declarations, and one workflow declares write access. Explicit least-privilege permissions would make the build and release process more transparent and safer.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.