Clear documentation, tests, release notes, and licensing support straightforward adoption. The workflow audit found no dangerous sinks, but all five action references are unpinned and the repository has no security policy.
88%
Total Score
100
100
100
75
No repository security policy was found. This is a transparency gap, though active maintenance and Dependabot partly reduce the concern.
The sole workflow was fully analyzed with no untrusted checkout, script injection, or audit findings, but all 5 of 5 action references are unpinned. The missing top-level permissions block is acceptable on its own and no write-wide token was observed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1|^2 | — | — |
composer/installers Version ^2|^1.0.12 | — | — |
jeroen/file-fetcher Version ^6 | — | — |
mediawiki/bootstrap Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.