The project has recent commits, two active contributors, tests, and release notes for this version. Workflow references are all unpinned, and the audit found low-confidence cache-poisoning hygiene issues; there is also no security policy.
82%
Total Score
100
100
94
83
Composer is used for build tooling, but no security scanning tool was detected. The missing scanner is a modest transparency gap, not evidence of unsafe code.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. Active commits and testing provide some compensating project evidence, but not a documented reporting path.
All three workflows were analyzed and none uses an untrusted checkout or script injection, and two scope permissions at job level. However, all 13 action references are unpinned, while the audit's three cache-poisoning findings are low-confidence hygiene concerns rather than standalone severe risks.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.