The package is well documented, licensed, and released regularly, with security scanning and a matching source repository. Maintenance depends on one contributor, while workflow references are mostly unpinned and the audit found high-confidence template-injection hygiene issues.
68%
Total Score
63
50
100
100
The release declares 26 runtime dependencies, a broad dependency surface for a command-line integration tool that increases maintenance and transitive-risk exposure.
The repository is user-owned rather than organization-owned, so the single-maintainer concentration provides no demonstrated organizational handoff capacity.
One contributor made all 5 recent commits, leaving the project dependent on a single individual for current maintenance capacity.
There are 7 open issues and no recent issue or pull-request activity, which is a modest transparency concern despite the recent release.
The audit analyzed all 7 workflows, but 36 of 37 action references are unpinned and it found high-confidence template-injection findings in release workflows; the low-confidence cache findings are hygiene only, and no dangerous trigger or untrusted checkout was reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^3.4|^4.0|^5.0|^6.0|^7.0 | — | — |
psr/container Version ^2.0 | — | — |
symfony/config Version ^7.4 | — | — |
symfony/finder Version ^5.4|^6.0|^7.0 | — | — |
psr/http-client Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.