All four workflow actions are unpinned, weakening build reproducibility. Tests, release notes, organization backing, and security tooling provide useful maintenance evidence, but recent commit activity is absent and no security policy is published.
70%
Total Score
75
90
75
The package has five releases since March 2022, but none in the last 12 months and the latest release was nearly two years ago at collection time. This indicates a meaningful slowdown, partly offset by recent repository activity.
The repository recorded zero commits and zero active maintainers in the last three months. That weakens evidence of active maintenance, despite the repository not being archived.
No repository security policy was found. This is a transparency gap for a package handling identity-number validation, though it is not by itself evidence of unsafe code.
Both workflows were analyzed successfully with no dangerous triggers, sinks, or audit findings, but all four action references are unpinned. The workflow setup is therefore broadly safe while still weaker on reproducibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/validator Version ^5.4||^6.4|^7.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.