The project is actively maintained by two contributors and backed by an organization, with tests, security scanning, and regular releases. Its command-line package has no README, and the workflow leaves all seven action references unpinned.
68%
Total Score
100
50
86
75
The manifest declares a proprietary license, with no recognized license text or license file in the package or repository. That creates a significant legal barrier for developers seeking an open-source dependency.
The package declares 10 runtime dependencies, including several Symfony components and a networking library. This is a meaningful dependency surface but not excessive for the reported client functionality.
The repository has no security policy. This weakens vulnerability-reporting transparency, though the reported security scanning provides partial compensation.
The workflow audit completed cleanly with no injection or high-confidence security findings, but all 7 action references are unpinned. Missing top-level permissions is acceptable here and does not offset the reproducibility risk of unpinned actions.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.4 | — | — |
symfony/config Version ^7.4 | — | — |
symfony/dotenv Version ^7.4 | — | — |
symfony/console Version ^7.4 | — | — |
symfony/process Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.