Two active contributors made 141 commits in the last three months, with organizational backing reducing handoff risk. The missing security policy and workflow hygiene leave avoidable maintenance and release-process concerns.
78%
Total Score
83
50
94
50
The release declares 25 runtime dependencies, a substantial integration surface that adds maintenance and transitive-dependency exposure, though the active project offsets some of that concern.
Two contributors were active, but the leading contributor made about 73% of recent commits; organizational ownership provides some ability to hand work off.
The project uses Just and Composer for builds, but no security-scanning tools were detected, leaving a release-quality gap.
No repository security policy was found, reducing transparency about vulnerability reporting and maintenance response.
All 28 action references are unpinned, one workflow grants top-level write permissions, and the audit found four high-confidence template-injection findings in split.yml; no untrusted trigger or checkout was detected, so this is workflow hygiene risk rather than a standalone severe dependency verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
twig/twig Version ^3.0 | — | — |
aimeos/map Version ^3.8 | — | — |
symfony/yaml Version ^7.3 || ^8.0 | — | — |
symfony/config Version ^7.3 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.