Clear licensing, a usable README, and a small dependency surface make adoption straightforward. Workflow caching needs cleanup, but the audit found no untrusted checkout or script injection.
78%
Total Score
75
100
100
75
No commits or active maintainers were recorded in the last 3 months, which is a maintenance concern despite the recent release and repository push.
The repository has no security policy. This is a transparency gap, though it is less significant for a development-only coding-standard configuration package.
The sole workflow was fully analyzed and had no untrusted checkout or script-injection findings, but all 3 action references are unpinned and the low-confidence cache-poisoning finding is a hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slevomat/coding-standard Version ^8.0 | — | — |
symplify/easy-coding-standard Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.