The package includes tests, release notes, a clear README, and no install-time scripts. Its small community, absent security policy, and unpinned workflow actions warrant routine review, while the recent release and active repository backing reduce abandonment concern.
78%
Total Score
88
100
88
75
The release includes a LICENSE.md and the repository also has a license file, but the declared MIT license conflicts with the detected Apache-2.0 text. That mismatch reduces licensing clarity despite the presence of licensing evidence.
No commits and no active maintainers were recorded in the last 3 months. This is a maintenance caution, though it is partly offset by the release and repository push recorded on the assessment date.
The repository uses Composer build tooling, but no security-scanning tool was detected. The missing scanner is a modest transparency gap rather than evidence that the package is unsafe.
The repository has no security policy. That leaves vulnerability reporting and response expectations unclear for a library used in service integrations.
The single workflow was fully analyzed, uses read-only permissions, and has no audited findings or untrusted checkout paths. However, both action references are unpinned, leaving avoidable supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ~5.0|~6.0|~7.0 | — | — |
symfony/config Version ~5.0|~6.0|~7.0 | — | — |
monolog/monolog Version ~1.22|^2.9|^3.0 | — | — |
symfony/serializer Version ~5.0|~6.0|~7.0 | — | — |
symfony/http-kernel Version ~5.0|~6.0|~7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.