Loads environment variables from `.env` to `getenv()`, `$_ENV`
54%
Total Score
caution
Usable with caveats: one release and no recent commits point to a thin maintenance track.
The repository is owned by a user account rather than an organization, so the single registry maintainer offers limited visible organizational backing.
This is the only release after about 10 months of package age, so there is little release history from which to judge sustained maintenance.
The repository recorded no commits and no active maintainers in the last three months, indicating currently thin maintenance activity.
The assessed version is not a prerelease, but it remains on the 0.x major line, which indicates a less mature compatibility commitment.
All seven analyzed action references are unpinned, and the audit found two high-confidence template-injection findings in annotate.yml. The same workflow also has a script-injection finding, while no untrusted checkout or privileged trigger was reported, so this is a meaningful hygiene and workflow risk rather than a standalone critical defect.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zero-to-prod/package-helper Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.