Clear documentation, tests, release notes, and recent commits support adoption. The workflow audit found a high-confidence template-injection issue and all 34 actions are unpinned, so CI deserves attention.
76%
Total Score
100
100
94
100
The repository has zero stars, forks, and watchers. This limits external validation, but popularity is supporting evidence and does not outweigh the active maintenance signals.
All eight workflows were analyzed, but all 34 action references are unpinned. The audit also found a high-confidence template-injection issue in coderabbit.yml alongside a workflow_run trigger and untrusted checkout in that workflow, making CI hygiene a real concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.8 | — | — |
symfony/asset Version ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/config Version ^6.0 || ^7.0 || ^8.0 | — | — |
twig/extra-bundle Version ^3.12 | — | — |
twig/string-extra Version ^3.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.