The project has clear organizational ownership, a stable version, and documented release changes. Workflow references are not pinned, and the repository lacks a security policy.
67%
Total Score
75
90
50
The package has 41 releases since January 2020, but its latest registry release was nearly two years ago and there were no releases in the last 12 months. This indicates a meaningful maintenance slowdown despite a strong historical cadence.
The repository had no commits and no active maintainers in the past three months. Although the repository was pushed in April 2025, the recent inactivity still raises abandonment concerns.
The repository has no security policy. Dependabot provides some security scanning, but there is no documented process for reporting or handling vulnerabilities.
All 10 analyzed action references are unpinned, and one high-confidence medium-severity finding identifies an archived action in the release workflow. No untrusted checkout, script injection, or broad top-level write permissions were found, limiting the impact to workflow hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ecphp/ecas Version ^4 | — | — |
ecphp/cas-bundle Version ^3 | — | — |
symfony/framework-bundle Version ^6.4 || ^7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.