The repository includes tests, a changelog, build tooling, and dependency scanning. GitHub Actions uses all 16 actions without pinning, and no security policy is published.
82%
Total Score
75
100
67
One contributor made 16 of 17 recent commits, so maintenance is concentrated despite a second active contributor. That creates a modest continuity concern for a user-owned project.
No repository security policy was found. This is a transparency gap, though it is partly offset by the project's active maintenance and Dependabot configuration.
All five workflows were analyzed without high-confidence findings or unsafe untrusted triggers, and permissions are not broadly writable. However, all 16 action references are unpinned, leaving a reproducibility and action-integrity hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sebastian/diff Version ^9.0||^8.0||^7.0.0||^6.0.1||^5.0||^4.0.3 | — | — |
symfony/finder Version ^8.0||^7.2.1||^v5.4.8 | — | — |
symfony/console Version ^8.0||^7.2.1||^v5.4.8 | — | — |
laravel/agent-detector Version ^2.0 | — | — |
stolt/list-skills-command Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.