The project has no commits or issue activity in the last three months, and its workflows use unpinned container images. It has a long release history, tests, a security policy, and organization backing.
65%
Total Score
67
93
100
The repository recorded zero commits and zero active maintainers during the last three months. This is a meaningful maintenance concern, although the release history shows continued registry publishing.
There were no new or closed issues or pull requests in the last month, and no pull requests were merged. Together with the absent three-month commit activity, this suggests currently limited visible project activity.
The repository name does not exactly match the package name and its README does not mention the package name. Although naming differences can occur for bundles or monorepos, the collected evidence leaves package-to-repository ownership less transparent.
All six workflows were analyzed with no untrusted checkouts or script injection, but both high-confidence findings concern unpinned container images and all 14 action references are unpinned. This is a workflow supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
symfony/config Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/console Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/http-kernel Version ^6.4 || ^7.0 || ^8.0 | — | — |
doctrine/mongodb-odm Version ^2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.