Clear documentation, tests, changelog, and licensing make integration straightforward. The organization-backed project remains active, while missing security guidance and entirely unpinned workflow actions warrant care.
81%
Total Score
100
100
50
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities; the available evidence does not show a compensating security process.
All 12 analyzed action references are unpinned, and one workflow has top-level write permissions; the audit also found high-severity cache-poisoning patterns only at low confidence plus high-confidence ad hoc package installs, so this is workflow hygiene risk rather than a standalone severe dependency risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.