The package includes tests, a changelog, release notes, a clear license, and a security policy. Its automated workflows use broad write permissions and leave all seven action references unpinned.
72%
Total Score
88
100
83
100
All 105 recent commits came from one contributor, creating a meaningful continuity risk; organization backing partly offsets the lack of contributor diversity.
The repository has no stars, forks, or watchers, so it has little external adoption evidence; this young package's strong release and commit activity compensates for that limited supporting signal.
Composer build tooling is present, but no security scanning tool was detected; the repository's separate security policy provides some compensating transparency.
Version 0.49.0 is not a prerelease, although the package remains below 1.0 and may still undergo breaking changes.
All four workflows were analyzed successfully with no injection or high-confidence audit findings. However, all seven action references are unpinned and three workflows grant top-level write permissions, creating avoidable maintenance and token-scope risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
milpa/command Version >=0.25.1 <1.0 | — | — |
milpa/event-store Version >=0.3 <1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.