The release is well documented, licensed, tested, and backed by an organization. Its workflows use entirely unpinned actions and contain high-confidence injection warnings, which add maintenance and build-integrity concerns.
66%
Total Score
75
93
50
The project has existed for about 11 years with 27 releases, but it has had no releases in the last 12 months. That recent pause lowers confidence in ongoing maintenance.
There were no commits and no active maintainers in the last three months. Combined with the lack of releases in the last year, this indicates currently inactive development.
The linked repository has no security policy. This is a transparency gap for reporting vulnerabilities, though it is partly offset by the project's organizational backing and Dependabot configuration.
All 21 action references are unpinned, and the audit found three high-confidence template-injection findings plus an archived action. No untrusted checkout or dangerous workflow trigger was found, so these are workflow hygiene and build-integrity concerns rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.