Clear licensing, repository tests, and release notes improve transparency. Pin this version and inspect the annotation workflow before relying on the project's automation.
58%
Total Score
50
100
94
100
One registry publishing account is listed, while the repository owner is a user rather than an organization. This suggests a thin publishing base and limited visible continuity if that maintainer becomes inactive.
The registry namespace and repository owner match, but the owner is a user account rather than an organization. This supports package identity while offering limited evidence of institutional backing.
The package has made five releases since November 2024, but none in the last 12 months; the latest release was about 12 months ago. This indicates materially slowed maintenance for a young package.
The audit analyzed all five workflows without failures, but found one high-confidence script-injection issue in annotate.yml, two high-confidence template-injection findings, all seven action references unpinned, and a release workflow with top-level write permissions. These are meaningful automation-hygiene concerns even though no dangerous trigger or untrusted checkout was reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zero-to-prod/regex-email Version ^71.0 | — | — |
zero-to-prod/package-helper Version ^1.1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.