It remains an early 0.x project with no security policy, and its two workflow actions are unpinned. Organization ownership, a matching repository, and a complete README provide useful context.
64%
Total Score
75
86
67
The repository recorded zero commits and zero active maintainers in the last 3 months. Although the release history is recent, this is a meaningful maintenance warning for a young package.
Composer build tooling is present, but no security scanning tools were detected. That leaves a repository hygiene gap, though it does not by itself indicate the package is unsafe.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. Organization backing provides some context but does not replace a published process.
Version v0.5.2 is not a stable major release, so its API may still change. It is not marked as a prerelease, which partly offsets the early-version risk.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, both action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^6.0|^7.0|^8.0 | — | — |
symfony/process Version ^6.0|^7.0|^8.0 | — | — |
vlucas/phpdotenv Version * | — | — |
open-telemetry/sdk Version * | — | — |
open-telemetry/exporter-otlp Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.