It has a clear MIT license, repository tests, and release notes for this version. Install-time scripting and wholly unpinned workflow actions add avoidable supply-chain exposure, while the missing security policy reduces transparency.
62%
Total Score
50
93
50
A post-install-cmd script runs during installation, adding execution behavior beyond ordinary dependency resolution and increasing supply-chain exposure.
The package has 9 releases over about 2 years, but none in the last 12 months; this is a meaningful maintenance concern despite a previously regular median interval of about 37 days.
The repository recorded 0 commits from 0 active maintainers in the last 3 months, which supports the concern that active maintenance has slowed or stopped.
No security policy was found, leaving vulnerability-reporting expectations unclear for a library that processes protected documents and archives.
All 10 analyzed action references are unpinned, which weakens build reproducibility. No untrusted checkout, script injection, dangerous trigger, or audit finding was reported, so this remains a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/mime Version ^7.1 | — | — |
symfony/process Version ^7.1 | — | — |
illuminate/support Version ^11.0 || ^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.