The repository includes tests, a substantial README, Composer audit tooling, and a source tree matching the package. A single maintainer and five stars limit resilience, while all eight workflow actions are unpinned.
63%
Total Score
50
100
75
Only one registry publisher is listed, which reduces publishing resilience and creates a thin maintainer base; the linked repository is user-owned rather than organization-backed.
The repository recorded 0 commits and 0 active maintainers in the last three months, which is a meaningful maintenance concern for a young package despite a recent push being recorded elsewhere.
No security policy was found in the linked repository, reducing transparency for vulnerability reporting, although Composer audit tooling provides some compensating security practice.
The workflow audit completed cleanly with no dangerous triggers or findings, but all 8 of 8 action references are unpinned, leaving the build exposed to moving action versions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.4 || ^7.0 | — | — |
symfony/config Version ^6.4 || ^7.0 | — | — |
symfony/http-kernel Version ^6.4 || ^7.0 | — | — |
symfony/twig-bundle Version ^6.4 || ^7.0 | — | — |
symfony/dependency-injection Version ^6.4 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.