It has a readable README, repository tests, and explicit licensing. The release also avoids install-time scripts, but its workflow actions are unpinned.
12%
Total Score
50
50
83
Packagist marks the entire package as abandoned, with no replacement supplied. This is a direct warning against taking a new dependency on the package.
The repository recorded no commits and no active maintainers in the last three months. This confirms that current maintenance capacity is absent.
The linked source repository is archived, and its last push was on July 10, 2024. An archived project is not expected to receive maintenance or fixes.
The package has 31 releases, but none in the last 12 months and its latest release was July 10, 2024. That supports the abandonment concern despite its earlier roughly monthly cadence.
All four workflows were analyzed with no reported audit findings or untrusted checkouts, but all nine action references are unpinned. The unpinned actions are a build-integrity hygiene concern, not the main reason this release is unfit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^3.9 | — | — |
webmozart/assert Version ^1.0 | — | — |
guzzlehttp/guzzle Version ~6.0 | — | — |
symfony/twig-bundle Version ^5.0 | — | — |
symfony/framework-bundle Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.