The repository is small and all recent commits come from one maintainer. Tests, release notes, a license, and security tooling provide useful safeguards, but workflow dependency pinning is weak.
68%
Total Score
50
94
100
Only two releases exist, with none in the last 12 months; the latest release is from May 2024, which raises freshness and maintenance concerns despite recent repository activity.
All recent commits came from one contributor, leaving maintenance dependent on a single person; the repository is user-owned, so there is no organization backing to offset that concentration.
The repository recorded two commits in the last three months, showing some ongoing activity, but the volume is modest for a library with no recent registry release.
All nine action references are unpinned, which weakens build reproducibility, and the audit found a high-confidence adhoc package installation; however, there are no high- or medium-severity findings and no untrusted checkout or script-injection sinks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache Version ^7.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
kevinrob/guzzle-cache-middleware Version ^5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.