The repository includes tests and the release is stable, but workflow dependencies are unpinned. Its organization backing and lack of deprecation help, but the source does not clearly identify the package.
35%
Total Score
50
79
100
The package has had no releases in the last 12 months, and its latest release was more than five years ago. This is strong evidence of abandonment despite six releases overall.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing that development stopped more than five years ago.
The linked repository name does not match the package name and its README does not mention the package, creating uncertainty about whether it is the correct source repository.
The single workflow was fully analyzed with no dangerous findings, but all three referenced actions are unpinned. That leaves avoidable build-integrity risk while remaining a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^4.2|^5.0 | — | — |
league/flysystem Version ^1.1 | — | — |
arcanedev/support Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.