The MIT license, tests, release notes, and matching organization-backed repository improve transparency. Maintenance has stopped since 2022, while the workflow uses two unpinned actions and has no security policy.
58%
Total Score
50
83
50
The latest release was published over four years ago, with no releases in the last 12 months. This is strong evidence of a stale package, though the release history contains eight releases and the current version is stable.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing that maintenance has effectively stopped.
The repository has no published security policy. This weakens vulnerability-reporting transparency, although it is less significant than the package's prolonged inactivity.
The workflow audit completed fully and found no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both analyzed actions are unpinned, leaving a modest reproducibility and dependency-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ddeboer/vatin Version ^2.2.2 | — | — |
symfony/config Version ^v5.4.3 || ^v6.0.3 | — | — |
symfony/validator Version ^v5.4.3 || ^v6.0.3 | — | — |
symfony/http-kernel Version ^v5.4.3 || ^v6.0.3 | — | — |
symfony/dependency-injection Version ^v5.4.3 || ^v6.0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.