The repository has tests, a changelog, release notes for this version, clear MIT licensing, and organization backing. The main remaining concerns are limited recent development evidence and workflow references that are not pinned.
67%
Total Score
75
100
88
67
The package is only 126 days old and has 51 releases, but all releases were published within the same day, so the history shows launch activity rather than an established release cadence.
The repository recorded zero commits and zero active maintainers during the last three months. For a package released only 126 days ago, this is a meaningful but not conclusive maintenance concern.
The linked repository is not archived, although its last push was 126 days ago, so the repository remains available but recent maintenance is limited.
No security policy is present in the repository. This is a transparency gap, though the package does provide Psalm scanning and the absence is not severe on its own.
The sole workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings, but all eight action references are unpinned, leaving builds exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
behat/behat Version ^3.22 || ^4.0 | — | — |
symfony/http-kernel Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/dependency-injection Version ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.