The project is actively backed by an organization, has recent releases, tests, and a clear package repository. Its release automation still exposes serious control-flow and credential-handling weaknesses, while every analyzed action reference is unpinned.
38%
Total Score
100
94
75
All 61 analyzed action references are unpinned, and high-confidence findings include template-injection patterns plus checkout credentials persisting into artifacts in build and publish workflows. The audit found no untrusted checkout trigger, but these release-workflow weaknesses remain a substantial supply-chain concern.
No repository security policy was detected, leaving disclosure and response procedures undocumented.
This release is a beta and 75% of recent releases are prereleases, so consumers should expect less stability than with a stable release.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sentry/sentry Version ^1.11 | — | — |
vlucas/phpdotenv Version ^3.4 | — | — |
brick/phonenumber Version ^0.4.1 | — | — |
symfony/polyfill-php80 Version ^1.23.1 | — | — |
segmentio/analytics-php Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.