The package includes tests in its repository, clear release notes, and a stable MIT license. Recent development has paused, and the release workflows use unpinned actions with two archived dependencies; this warrants checking future maintenance before upgrading.
68%
Total Score
50
100
88
67
There has been only 1 release in the last 12 months, despite 38 releases since October 2020. This suggests a slower maintenance cadence, though the package did receive a recent release.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Combined with the low recent release count, this is evidence of currently limited maintenance activity.
Composer and Box provide build tooling, but no security scanning tools were detected. The build process is defined, while automated security coverage is limited.
The repository has no security policy. That reduces transparency for reporting and handling vulnerabilities, although it does not by itself show that the package is unsafe.
Both workflows analyze cleanly and have no untrusted checkouts or script injection, but all 19 action references are unpinned and two high-confidence findings identify archived actions. The cache-poisoning finding is low confidence and is only a hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^6.0 | — | — |
symfony/process Version ^6.0 | — | — |
symfony/filesystem Version ^6.0 | — | — |
symfony/http-client Version ^6.0 | — | — |
thecodingmachine/safe Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.