Documentation, repository tests, and a security policy are in place. Recent work is concentrated in one contributor, and workflow action references are not pinned.
78%
Total Score
83
100
100
100
All three recent commits came from one contributor, giving the project a concentrated maintenance base. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Both workflows use read-only permissions, have no untrusted checkouts or script injection findings, and the audit completed fully. However, all 7 analyzed action references are unpinned, leaving a reproducibility and action-supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.