Documentation, tests, and release notes provide useful support for adoption. Ongoing maintenance is the main concern, with quiet issue activity and unpinned workflow actions increasing upkeep and build-integrity risk.
68%
Total Score
50
100
94
75
The package has 23 releases over nearly eight years, but its latest release was about 16 months ago and there were no releases in the last 12 months. This points to slowing maintenance despite a historically regular release cadence.
There were no new or closed issues and no new or merged pull requests in the last month, while 26 issues and 27 pull requests remain open. This is concrete evidence of currently quiet project activity.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap for a maintained library.
All three workflows were analyzed with no dangerous triggers, untrusted checkouts, or audit findings, and they avoid broad top-level write permissions. However, all 8 action references are unpinned, so workflow dependencies can change without a reviewed commit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^3.4 || ^4 || ^5 || ^6 || ^7.0 | — | — |
justinrainbow/json-schema Version ^5.2 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.