A clear README, release notes, license, and six recent contributors improve day-to-day confidence. The missing security policy and concentrated lead authorship leave less backup when issues arise.
68%
Total Score
75
100
100
75
Six contributors were active recently, but the leading contributor made about 72% of commits. That concentration is a modest continuity risk despite the broader contributor set.
The repository has no security policy. That leaves vulnerability reporting and response expectations undocumented for users and maintainers.
All 21 analyzed action references are unpinned, and the audit found one script-injection issue plus high-confidence template-injection findings in release workflows. The findings are workflow hygiene risks rather than standalone proof that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/deprecation-contracts Version ^3.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.