Tests, a consumer README, Composer tooling, and Dependabot provide a solid project base. Two unpinned workflow references plus inherited secrets and an archived action weaken build hygiene.
62%
Total Score
50
100
90
67
This package has only one release, published about four years ago, with no releases in the last 12 months. That leaves current compatibility and maintenance uncertain.
The repository recorded no commits and no active maintainers during the last three months. The repository is not archived, but recent activity does not demonstrate active maintenance.
The linked repository has no security policy, leaving vulnerability-reporting expectations unspecified. This is a modest transparency gap for a small project rather than a severe dependency risk.
All 8 analyzed action references are unpinned, and the audit found high-confidence use of inherited secrets plus an archived action. Workflows have no top-level permissions block, which is acceptable on its own, but these concrete hygiene issues lower transparency and build safety.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.