Clear licensing, a documented security policy, repository tests, and a small dependency footprint support adoption. Workflow references are unpinned, weakening build reproducibility.
82%
Total Score
67
100
100
100
All three recent commits came from one contributor, creating a concentrated maintenance dependency; organization backing partly reduces handoff risk.
Only three commits were made in the last three months, showing some recent activity but a relatively light maintenance pace.
Both workflows were analyzed without dangerous triggers, untrusted checkouts, script injection, or audit findings, but all four action references are unpinned, weakening reproducibility.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-865125 netcarver/textile is vulnerable to Cross-Site Scripting (XSS) in versions 0.0.1 - 4.1.4. | 0.0.1 - 4.1.4 | High |
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.