The package includes tests, a clear README, a matching repository, and no install-time scripts. Its small user base, absent security policy, and unpinned workflow actions leave limited external assurance.
78%
Total Score
50
100
100
67
There were no commits from active maintainers during the last three months, which weakens evidence of continuous development, although the recent release and issue activity provide some compensation.
The repository has no published security policy, leaving reporting and response expectations unclear for users of the package.
The workflow was fully analyzed, uses read-only permissions, and has no untrusted checkout or injection findings. However, both of its action references are unpinned, so they can change without a version review.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
behat/behat Version ^4.0 | — | — |
symfony/config Version ^5.4 || ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/event-dispatcher Version ^5.4 || ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/dependency-injection Version ^5.4 || ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.