The package includes tests, a changelog, release notes, and a clear MIT license. The missing security policy and weak workflow pinning reduce transparency and build reproducibility.
68%
Total Score
50
100
50
There were no commits and no active maintainers in the last three months. Although the release itself was recent within the observed history, the current inactivity raises maintenance concern.
There were no issues or pull requests handled in the last month, with four issues still open; this is a mild sign of limited current project activity.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
All four workflows were analyzed completely and had no dangerous audit findings or broad write permissions, but all 12 referenced actions are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/messenger Version ^6.4|^7.4|^8.0 | — | — |
symfony/http-client Version ^6.4|^7.4|^8.0 | — | — |
symfony/http-kernel Version ^6.4|^7.4|^8.0 | — | — |
symfony/dependency-injection Version ^6.4|^7.4|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.