Documentation, tests, release notes, and a matching source repository make the package transparent to adopt. GitHub Actions still use floating container images and have a high-confidence template-injection finding, so maintenance and build hygiene deserve scrutiny.
65%
Total Score
50
93
75
The package has 14 releases since December 2019, but none in the latest 12 months and the last release was over two years ago. This points to slowed maintenance, despite a previously active release cadence.
The repository recorded zero commits and zero active maintainers in the latest three-month window. The repository was pushed in March 2025, so this is a meaningful recent inactivity signal rather than evidence of abandonment by itself.
The repository has no security policy, leaving no stated process for reporting or handling vulnerabilities. Dependabot provides some compensating security tooling, but it does not replace a documented response process.
All 10 analyzed action references are unpinned, five workflows use floating container images, and the audit found high-confidence template injection and bot-condition issues. No untrusted checkout or script-injection path was found, limiting the impact to build and release hygiene rather than a severe demonstrated exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
cocur/slugify Version ^3.2 || ^4.0 | — | — |
symfony/console Version ^3.4||^4.4||^5.0||^6.0 | — | — |
erusev/parsedown Version ^1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.