Clear licensing, tests, release notes, and a two-person contributor base improve confidence. Pinning is the main remaining workflow hygiene gap; no dangerous triggers or audit findings were reported.
84%
Total Score
83
100
94
75
The repository is user-owned rather than organization-owned, so the small maintainer and contributor base provides less formal handoff capacity, though recent activity remains visible.
Composer is used for builds, which is appropriate, but no security-scanning tooling is reported; this is a minor transparency gap rather than evidence of poor maintenance.
The repository has no security policy, leaving vulnerability-reporting expectations unclear for a web-facing database import tool.
Both workflows scope permissions at the job level and have no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 6 action references are unpinned, creating a workflow reproducibility and action-integrity gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.