The package is licensed, documented, and supported by repository tests, release notes, and Dependabot. Its workflows leave container images unpinned, adding avoidable build risk.
60%
Total Score
50
100
50
The repository recorded zero commits and zero active maintainers during the last three months. That is a meaningful maintenance warning, despite the recent release history.
The repository has no security policy. For a package that executes Docker commands and supports remote hosts, this leaves security-reporting and response expectations unclear.
All three workflows were analyzed, with no untrusted triggers or script-injection sinks, but the audit found a high-confidence unpinned container image and all eight action references are unpinned. This is avoidable workflow supply-chain hygiene risk, not evidence that the package is malicious.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ^7.0 | — | — |
spatie/macroable Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.