A clear README, repository tests, MIT licensing, and Dependabot provide useful maintenance and transparency signals. GitHub Actions has a script-injection finding and all seven action references are unpinned, so release automation needs care.
67%
Total Score
50
90
50
The package has five releases since December 2024, but none in the last 12 months; the long publishing gap lowers confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the registry's lack of recent releases and increasing abandonment risk.
All seven analyzed action references are unpinned, and the audit found two high-confidence template-injection findings plus one script-injection count in annotate.yml. No pull_request_target or workflow_run trigger was reported, so this is workflow hygiene risk rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zero-to-prod/omdb-api Version ^1.0.1 | — | — |
zero-to-prod/data-model Version ^81.12 | — | — |
zero-to-prod/omdb-models Version ^1.0 | — | — |
zero-to-prod/transformable Version ^71.1 | — | — |
zero-to-prod/package-helper Version ^1.1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.