A single maintainer and fully unpinned workflow actions leave some resilience and build-reproducibility concerns. The repository has tests, security guidance, and a clear consumer README.
80%
Total Score
70
100
100
100
Only one registry account has publish access. This is a modest publishing-resilience concern, though repository activity shows that the account is currently maintaining the project.
The repository is owned by an individual user rather than an organization, so the single-contributor concentration and one-account publishing model are meaningful resilience limitations.
All seven recent commits came from one contributor, so maintenance depends heavily on a single person despite the project's recent activity.
Both workflows were analyzed without failed files or high-confidence findings, and no untrusted checkout or injection sink was found. All five action references are unpinned and one workflow grants top-level write access, which weakens reproducibility and least-privilege hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/mime Version ^7.4.0 || ^8.0.0 | — | — |
saloonphp/xml-wrangler Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.