The package includes tests, readable documentation, release notes, and a clear MIT license. Its workflow has no audited dangerous findings, but all four action references are unpinned.
67%
Total Score
50
100
93
100
Only one release has been published, with no established release cadence yet. This limits evidence of long-term maintenance maturity.
One contributor made 100% of the recent commits, leaving no demonstrated contributor redundancy. The repository owner is an individual, so there is no organization backing shown to offset this concentration.
Only one commit was recorded in the last three months, from one active maintainer. Recent activity exists, but the observed maintenance pace is thin.
The only workflow was fully analyzed with no dangerous audit findings, and it scopes permissions at job level. However, all four action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
byjg/jinja-php Version ^6.0 | — | — |
symfony/console Version ^5.4|^6.2|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.