The project has recent releases, tests, documentation, a security policy, and active repository tooling. Do not adopt this release until the package deprecation is resolved; workflow pinning and single-contributor maintenance add further risk.
20%
Total Score
67
88
88
Packagist marks the package deprecated at package scope and provides no distinct replacement, making the release unsuitable to adopt until that status is clarified.
One contributor made all 2 recent commits, leaving maintenance dependent on a single active contributor even though the repository owner is an organization.
There were 2 commits in the last 3 months, so maintenance is present but limited in volume.
All four workflows use read-only permissions and the audit completed fully, but all 11 action references are unpinned. The only reported cache-poisoning finding has low confidence, so it is a hygiene concern rather than a severe finding.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
webmozart/assert Version ^1.11|^2.4 | — | — |
symfony/serializer Version ^7.0|^8.0 | — | — |
symfony/http-client Version ^7.0|^8.0 | — | — |
symfony/property-access Version ^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.