A single maintainer and many unpinned workflow actions leave some continuity and build-reproducibility risk. MIT licensing, no install scripts, and a clean workflow audit otherwise reduce adoption friction.
82%
Total Score
75
100
75
Two contributors are active, but the leading contributor made 90.9% of recent commits; because the owner is an individual rather than an organization, this remains a continuity concern.
The repository has no published security policy, leaving vulnerability-reporting expectations and response guidance unclear.
Both workflows were analyzed successfully with no dangerous audit findings and one workflow explicitly uses read-only permissions. However, 11 of 17 action references are unpinned, creating a build reproducibility and action-tampering hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0|^3.0 | — | — |
symfony/yaml Version ^6.4|^7.0|^8.0 | — | — |
symfony/console Version ^6.4|^7.0|^8.0 | — | — |
symfony/http-client Version ^6.4|^7.0|^8.0 | — | — |
symfony/dependency-injection Version ^6.4|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.