The package is licensed, tested, documented, and backed by an organization with a stable release history. Unpinned workflow actions and the missing repository/package connection add maintenance and transparency concerns.
65%
Total Score
75
100
94
50
A post-install command runs during installation, which adds execution-time behavior and some supply-chain exposure compared with a package without lifecycle scripts.
There were no commits and no active maintainers in the last three months, a meaningful recent slowdown that raises maintenance risk even though the repository was pushed recently.
The repository name does not match the package name and its README does not mention the package, so the linkage is not clearly demonstrated and could reflect repository piggy-backing.
No security policy is present, leaving vulnerability reporting and response expectations undocumented; this is a transparency gap, not evidence of an unsafe release.
All four workflows were analyzed without high-confidence findings or untrusted-trigger sinks, but all three action references are unpinned, reducing build reproducibility and action-integrity assurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
eluceo/ical Version 2.14 || 2.15 | — | — |
symfony/yaml Version ^6.3 || ^7.0 | — | — |
symfony/config Version ^6.3 || ^7.0 | — | — |
rlanvin/php-rrule Version ^2.5 | — | — |
symfony/messenger Version ^6.3 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.