It includes a README, tests, MIT licensing, and organization backing, which support adoption. The workflow uses 14 unpinned actions, and the project has no security policy or scanning.
58%
Total Score
75
88
67
The package has five releases, all within its first day, followed by about 11 months without a release. This suggests an unfinished or inactive release cadence despite the package being about one year old.
There were zero commits and zero active maintainers during the last three months measured. Combined with the long gap since the last release, this is a meaningful maintenance concern.
Composer build tooling is present, but no security scanning tools were detected. That weakens automated oversight for a package integrating an external AI service.
The repository has no security policy. This is a transparency and response-process gap, though it is moderated by the package's small scope and available tests.
All 14 analyzed action references are unpinned, which leaves workflow dependencies exposed to changing upstream code. The audit found no dangerous triggers, untrusted checkouts, script injection, or high-confidence findings, and the workflow has no top-level write permission.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.3 | — | — |
symfony/config Version ^7.3 | — | — |
ibexa/core-search Version ~5.0 | — | — |
ibexa/connector-ai Version ~5.0 | — | — |
symfony/http-client Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.