Tests, a clear license, and organization backing provide useful support for adoption. The missing security policy and weak workflow pinning leave room for maintenance and build-integrity improvements.
80%
Total Score
100
100
94
67
The package has existed for about 8 years and released once in the last 12 months, with a median interval of about 14 months. That is slower than a frequently updated library, but the latest release is recent and repository activity is present.
The repository has no security policy. This is a transparency gap for reporting vulnerabilities, although it is not evidence that the release is unsafe.
All 14 analyzed action references are unpinned, which weakens build reproducibility. The audit found high-confidence template-injection patterns, but no untrusted checkout or script-injection sink, so these remain workflow hygiene concerns rather than a severe dependency-health risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.