Clear licensing, tests, release notes, and security scanning improve transparency. The small release history, single publisher, missing security policy, and loose workflow pinning leave maintenance and build-integrity concerns.
58%
Total Score
25
100
93
67
The repository has no commits and no active maintainers in the last 3 months. Combined with the roughly 6-month gap since the latest release, this is the strongest abandonment concern.
Only one account has registry publishing access. The linked repository is user-owned rather than organization-owned, so there is no provided backing signal to compensate for this narrow publisher base.
The package is about 6 months old but has only two releases, both published within minutes on its first day. That limited history provides little evidence of a sustained maintenance cadence.
The repository has no security policy. For a package focused on security checks and application protection, that is a meaningful transparency gap.
Both workflows were analyzed without audit findings or untrusted-trigger sinks, but all seven action references are unpinned and the release workflow grants top-level write permissions. The broad token is only a mild concern here because no untrusted workflow path was observed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.