Composer package to warm up website caches, based on a given XML sitemap
48%
Total Score
unhealthy
Risky: one release in over two years and no recent commits point to abandonment risk.
Only one release exists, published about 2 years and 4 months ago, with no releases in the last 12 months. This is strong evidence of limited ongoing maintenance.
The repository recorded no commits and no active maintainers in the last 3 months, reinforcing the concern that development has stopped.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, though it does not outweigh the stronger maintenance evidence by itself.
All four workflows were analyzed, but all 40 action references are unpinned. The audit also reports high-confidence template-injection findings in the release workflow and an archived action in the test workflow; the low-confidence cache findings are only hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cuyz/valinor Version ^1.3 | — | — |
symfony/yaml Version ^5.4 || ^6.0 || ^7.0 | — | — |
guzzlehttp/psr7 Version ^2.0 | — | — |
symfony/console Version ^5.4 || ^6.0 || ^7.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.