The repository has tests, security scanning, a security policy, and recent pull-request activity. Prefer a newer release if one is available, since this exact version is old.
68%
Total Score
75
100
94
83
The package has had no registry release in about 2 years and 9 months, with no releases in the last 12 months. This materially raises freshness and maintenance risk despite the repository showing recent activity.
There were no commits and no active maintainers in the last three months. Recent pull-request activity and a recent repository push partly offset this, but direct commit momentum remains weak.
All 16 analyzed action references are unpinned, which weakens build reproducibility and action supply-chain hygiene. The audit found no dangerous triggers, untrusted checkouts, script injection, or other reported findings, and one workflow uses read-only permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache Version ^7.0 | — | — |
guzzlehttp/guzzle Version ^7.0 <8.0 | — | — |
kevinrob/guzzle-cache-middleware Version ^5.1 <6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.