The repository includes tests, a clear README, release notes for this version, MIT licensing, and automated security scanning. Its very short history provides little evidence of sustained maintenance, while all eight CI action references are unpinned and no security policy is published.
63%
Total Score
50
93
67
Only two releases exist and the package is one day old, so there is not yet enough history to demonstrate sustained maintenance or long-term stability.
The repository shows zero commits and zero active maintainers over the last three months. Because the project is only one day old, this is limited evidence rather than proof of abandonment, but it leaves maintenance capacity unestablished.
No repository security policy was found, leaving disclosure and response expectations undocumented for a package with application-facing code.
The single workflow was fully analyzed with no untrusted checkout, injection, or high-severity findings, but all 8 of 8 action references are unpinned. The missing top-level permissions block is acceptable on its own and is not a write-permission risk here.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sulu/sulu Version ~3.0 | — | — |
twig/twig Version ^3.0 | — | — |
symfony/uid Version ^6.4 || ^7.0 | — | — |
doctrine/orm Version ^2.17 || ^3.0 | — | — |
doctrine/dbal Version ^3.6 || ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.