The repository includes tests, release notes, security tooling, and a matching source tree. One-person publishing and broad unpinned workflow actions add maintenance and build-integrity concerns.
58%
Total Score
50
100
94
88
A single registry maintainer creates some continuity risk, although the linked repository and release history show this is an individually maintained project rather than an unowned package.
The repository owner is a user account rather than an organization, so the single publisher and limited contributor evidence are not offset by visible organizational backing.
The package has made no registry release in about 19 months, after five releases in its first month. That prolonged release silence raises abandonment risk despite the repository remaining available.
There were no commits or active maintainers in the last three months, consistent with the long release gap. This weakens evidence of ongoing maintenance.
All 13 analyzed action references are unpinned, creating avoidable build-integrity risk. The audit also found high-confidence template-injection findings and a script-injection finding in annotate.yml; the low-confidence GITHUB_ENV finding is only a hygiene concern here because no untrusted checkout was reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^7.2 | — | — |
zero-to-prod/url Version ^82.0 | — | — |
zero-to-prod/data-model Version ^81.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.