It includes a README, tests, changelog, and matching MIT licensing. The workflow audit found all seven action references unpinned, while no security policy is present and recent repository activity is quiet.
76%
Total Score
67
94
50
The repository had zero commits and zero active maintainers in the last 3 months, indicating a recent pause in development, although the June 2026 release shows the project has not been abandoned outright.
There were no new or closed issues or pull requests in the last month, with 6 issues and 2 pull requests still open; this suggests limited recent maintenance activity.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance-hygiene gap.
The repository has no security policy. That does not establish a vulnerability, but it reduces transparency about how security issues are reported and handled.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 7 action references are unpinned, which is a supply-chain hygiene gap, and the workflow has no top-level permissions block.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^5.4 || ^6 || ^7 || ^8 | — | — |
symfony/process Version ^5 || ^6 || ^7 || ^8 | — | — |
consolidation/config Version ^2 || ^3 | — | — |
consolidation/site-alias Version ^3 || ^4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.