The project has maintained releases, clear documentation, tests in the repository, and organization backing. All 13 workflow actions are unpinned, and the repository has no security policy, leaving avoidable maintenance and supply-chain hygiene gaps.
88%
Total Score
100
100
100
75
No security policy is present in the repository. This is a transparency and reporting gap, though it is not by itself evidence that the release is unsafe.
All five workflows were analyzed with no reported audit findings and no untrusted checkout or script-injection sinks. However, all 13 action references are unpinned, and two workflows grant top-level write access, creating avoidable workflow hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^6.4|^7.0|^8.0 | — | — |
spatie/image-optimizer Version ^1.7.5 | — | — |
spatie/temporary-directory Version ^2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.