The project has clear organizational backing, tests, release notes, and security tooling. Its recent development activity is quiet, and all eight workflow actions are unpinned, leaving maintenance and build-integrity caveats.
67%
Total Score
75
94
100
The package has 23 releases over roughly four years, but only one release in the past 12 months; this suggests a slower cadence without proving abandonment.
The repository recorded zero commits and zero active maintainers in the past three months, which is a meaningful maintenance concern despite a recent release and push shown elsewhere.
The only workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but all 8 of 8 action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.2 || ^7.0 | — | — |
symfony/config Version ^6.2 || ^7.0 | — | — |
symfony/console Version ^6.2 || ^7.0 | — | — |
symfony/process Version ^6.2 || ^7.0 | — | — |
composer/composer Version ^2.7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.