The repository has tests, a changelog, and active organizational ownership. However, this release is the sole publication from 2018, while the current workflow audit finds all 10 actions unpinned and two high-confidence template-injection findings.
61%
Total Score
83
100
88
67
This package has one release, published about eight years ago, with no releases in the last 12 months. That leaves little evidence of a maintained release stream.
Only one commit came from one active maintainer in the last three months. Recent activity exists, but it is too sparse to demonstrate a strong maintenance cadence.
The repository has no security policy. This is a transparency and response-process gap, though it is not by itself evidence that the code is unsafe.
Version 0.1.0 is not a stable major version, although it is not marked as a prerelease. The early version increases uncertainty for a dependency with only one release.
All 10 analyzed action references are unpinned, and the audit reports two high-confidence template-injection findings in a migration workflow. The workflows use no dangerous untrusted triggers or writable top-level tokens, which limits the severity, but the automation still needs remediation.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nailsapp/common Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.