Regular releases, a current repository, clear licensing, and documented usage support dependable adoption. Single-contributor recent activity and no security policy add upkeep uncertainty; workflow concerns should be corrected before trusting release automation.
78%
Total Score
67
100
75
One contributor made all recent commits, concentrating current project knowledge and increasing handoff risk; organization backing provides some compensation but does not remove the concentration.
The repository recorded 8 commits in the last 3 months, but all came from one active maintainer, leaving limited recent maintenance capacity.
The repository has no published security policy, leaving vulnerability reporting and response expectations less transparent.
All 28 analyzed action references are pinned and no untrusted checkout or injection sink was detected, but two high-confidence template-injection findings and one workflow with top-level write permissions weaken release-workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.3.3 | — | — |
nyholm/psr7 Version ^1.5 | — | — |
cuyz/valinor Version ^2.2 | — | — |
symfony/yaml Version ^5.4 || ^6.4 || ^7.4 || ^8.0 | — | — |
cocur/slugify Version ^4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.