Clear documentation, a matching repository, organization backing, and an MIT license support adoption. The project has no recent commit activity, lacks a security policy, and its workflow dependencies are all unpinned.
73%
Total Score
67
100
93
75
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, although the recent release history shows the project is not clearly abandoned.
There were no new or closed issues or pull requests in the last month, with one open pull request; this supports the picture of currently quiet maintenance but is not abandonment by itself.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so vulnerability-reporting and response expectations are not documented.
The single workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but all 7 action references are unpinned. This is a workflow reproducibility and supply-chain hygiene gap, not a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^4 || ^5 || ^6 || ^7 || ^8 | — | — |
symfony/console Version ^4 || ^5 || ^6 || ^7 || ^8 | — | — |
dflydev/dot-access-data Version ^1.1.0 || ^2 || ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.