All six workflow actions are unpinned, and the declared GPL-2.0-or-later conflicts with the detected GPL-3.0 license file. The repository is linked and unarchived, with a substantial README for installation and use.
48%
Total Score
50
63
The latest registry release was over five years ago, with no releases in the last 12 months. That is a substantial abandonment concern for a package being adopted at this version.
The package declares GPL-2.0-or-later and includes a license file, but the detected file text is GPL-3.0. The release is licensed, though the declaration and file should be reconciled before adoption.
The repository had no commits and no active maintainers in the last three months, which provides little evidence of ongoing maintenance despite the later repository push recorded elsewhere.
The single analyzed workflow has no untrusted trigger or audit finding, but all 6 referenced actions are unpinned. That leaves routine build dependencies exposed to changes in upstream action references.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
powerbuoy/sleek-acf Version ^2.0 | — | — |
powerbuoy/sleek-core Version ^3.0 | — | — |
powerbuoy/sleek-menu Version ^1.0 | — | — |
powerbuoy/sleek-login Version ^2.0 | — | — |
powerbuoy/sleek-utils Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.