A small dependency footprint, repository tests, release notes, and a security policy support adoption. Low activity and unpinned workflow actions reduce confidence in ongoing maintenance and build reproducibility.
61%
Total Score
75
100
94
100
The latest registry release was more than four years ago, with no releases in the last 12 months. That materially raises abandonment and compatibility risk.
There were no commits and no active maintainers in the last three months. Combined with the stale release history, this indicates weak current maintenance.
All 31 analyzed action references are unpinned, which weakens build reproducibility and makes workflow dependencies harder to control. The audit found no untrusted checkout, injection, dangerous trigger, or high-severity finding, so this is a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.