The package includes consumer documentation, repository tests, security scanning, and no install-time scripts. Its workflows leave both actions unpinned and the project has no security policy, while registry publishing has been inactive since 2019.
70%
Total Score
100
92
75
Only two releases exist, with none in the last 12 months and the latest published in April 2019. Recent repository commits provide some maintenance evidence, but the assessed registry release is still materially old.
No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented.
The complete audit found no dangerous triggers, untrusted checkouts, script injection, or high-severity findings. However, both analyzed action references are unpinned, which is a workflow supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/event-dispatcher Version >=2.8.26 | — | — |
detain/myadmin-plugin-installer Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.