The MIT license, tests, changelog, and CodeQL support transparent maintenance. A missing security policy and four unpinned workflow actions are minor hygiene gaps.
88%
Total Score
100
100
67
The repository has no published security policy, which leaves vulnerability-reporting expectations unclear for a payment integration. This is a transparency gap, but active commits and CodeQL provide partial compensation.
Both workflows were analyzed without audit findings, and permissions are scoped or read-only where declared. Four of seven action references are unpinned, a minor reproducibility and update-safety gap without an accompanying untrusted trigger or dangerous sink.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.