The package is licensed, tested, documented, and has a current stable release. Build tooling and automated scanning help, but no published security policy leaves a transparency gap.
72%
Total Score
67
94
50
The project has released for more than 8 years and published version 4.0.6 recently, but only one release appeared in the last 12 months and the median interval is about 203 days.
All four recent commits came from one contributor, so maintenance could be disrupted if that person becomes unavailable. Organization backing provides some handoff capacity, but no second recent contributor is shown.
Four commits were made in the last 3 months, showing current activity, but the pace is modest and comes from only one active maintainer.
The repository has no published security policy, leaving developers without a documented process for reporting and handling vulnerabilities.
All three workflows were analyzed, but every action reference is unpinned; the audit also found a high-confidence unpinned container image and a bot-condition issue. One workflow grants top-level write permission, though no untrusted checkout or script injection was detected.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.0 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.