It is licensed, documented by release notes, and backed by repository tests. The source remains available and matches the package, but limited recent development and weak workflow hygiene reduce confidence.
64%
Total Score
75
88
67
The package has 26 releases since November 2015, but its latest release was in December 2022 and it had no releases in the last 12 months. This indicates a long release gap for a package consumers may still depend on.
There were no commits and no active maintainers in the three months measured, which suggests limited ongoing development. The recent repository push partly offsets but does not remove this concern.
The repository uses Make and Composer build tooling, but no security-scanning tools were detected. This is a modest transparency and hygiene gap rather than evidence of abandonment.
No repository security policy was found. For a package that ships executable shell-completion tooling, this weakens the documented vulnerability-reporting process.
The single workflow was fully analyzed with no detected injection sinks or high-confidence audit findings, but all 3 of 3 action references are unpinned. The absence of a top-level permissions block is acceptable on its own, while unpinned actions leave avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^2.5|^3|^4|^5|^6 | — | — |
symfony/process Version ^2.5|^3|^4|^5|^6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.