The repository was updated recently and includes tests, a changelog, security tooling, and a security policy. Maintenance is concentrated in one contributor, while workflow references are unpinned and the release workflow has a low-confidence cache warning.
24%
Total Score
67
88
83
Packagist marks the entire package as abandoned, even though the listed replacement is the same package. This registry status is a severe adoption and support warning.
All two recent commits came from one contributor, leaving maintenance dependent on a single active person. Organization ownership provides some handoff capacity but does not remove the concentration risk.
There were two commits in the last 3 months, so maintenance is present but limited in volume.
All four workflows use read-only permissions and the audit completed fully, but all 11 action references are unpinned. The only reported cache-poisoning issue has low confidence, so it is a hygiene concern rather than a severe finding.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-client Version ^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.