The package has a stable release history, an organization-backed repository, and no install scripts. Its workflows have no audited dangerous findings, though action references are unpinned.
68%
Total Score
75
83
75
The repository recorded no commits and no active maintainers during the last three months. Although the release was recently pushed, the lack of ongoing commit activity is a maintenance concern.
The repository name does not match the package name and its README does not mention the package. This creates some uncertainty that the linked repository is the intended source, even though the repository is under the matching organization.
The repository uses Composer build tooling, which fits this package, but no security scanning tools were detected. For this small plugin, that is a modest transparency gap rather than a severe risk.
Both workflows were analyzed without dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, leaving them exposed to upstream reference changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.