It has clear licensing, a useful README, repository tests, and no install-time scripts. The workflow uses three unpinned actions and lacks a security policy, while the otherwise matching source repository provides some continuity.
58%
Total Score
50
83
75
The latest registry release was over five years ago, with no releases in the last 12 months. Sixteen releases over the package's earlier history show prior activity but do not offset the prolonged release gap.
The repository had zero commits and zero active maintainers in the last three months. A push in June 2024 shows the repository was not always dormant, but current maintenance capacity is weak.
No security policy was found in the linked repository, reducing transparency for reporting and handling vulnerabilities. The repository's other tooling and clean workflow audit provide limited compensation but do not replace a policy.
All three analyzed action references are unpinned, which weakens build reproducibility. The audit found no untrusted checkouts, injection paths, or high-severity findings, so this remains a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^4.3||^5.0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.