The package is well documented and released with notes, while the repository shows recent work from two contributors. Workflow checks found high-confidence script and template-injection concerns, broad app permissions, and all 18 actions unpinned.
72%
Total Score
67
100
100
100
The repository is owned by an individual rather than an organization, so the small maintainer and contributor base represents a genuine continuity risk.
Commit activity is evenly split between two contributors, avoiding single-contributor concentration, though the overall contributor base remains small.
The audit completed all six workflows but found one high-confidence script-injection issue, two high-confidence template-injection findings, a blanket GitHub App token permission finding, and all 18 action references unpinned. The absence of untrusted checkouts and dangerous triggers limits the exposure, but these remain meaningful workflow-hygiene concerns.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.