Release activity, tests, release notes, and organization backing provide useful maintenance evidence. The repository lacks a security policy, and its two workflow actions are unpinned. The recent pause in commits is worth monitoring despite the latest release.
62%
Total Score
75
93
50
The repository recorded zero commits and zero active maintainers in the last 3 months. The release pushed today and the recent release cadence partly compensate, but the short-term development pause still lowers confidence in ongoing maintenance.
The repository has no security policy. This weakens vulnerability-reporting transparency for a library, although composer-audit provides some separate security tooling.
Version 0.13.0 is not a stable major release, but it is not a prerelease and recent releases have no prerelease share. The 0.x major version signals API stability may still be evolving, rather than abandonment.
The complete audit found no dangerous triggers, untrusted checkouts, script injection, or high-confidence findings, and the workflow does not grant top-level write access. However, both analyzed action references are unpinned, which leaves the build exposed to moving action code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.8 | — | — |
symfony/uid Version ^7.1|^8.0 | — | — |
symfony/config Version ^7.1|^8.0 | — | — |
symfony/console Version ^7.1|^8.0 | — | — |
symfony/http-client Version ^7.1|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.