Documentation and release notes are clear, and the package has no install-time scripts. Workflow actions are unpinned and the repository lacks a security policy, while the package-to-repository reference is weak.
82%
Total Score
100
100
94
83
The repository name does not match the package name and its README does not mention the package, creating a caution that the linked repository may not clearly identify the published package. The matching FriendsOfBehat organization and SymfonyExtension project context partly reduce that concern.
No security policy was found in the repository. This is a transparency gap for a maintained integration package, although it does not by itself indicate unsafe code.
The sole workflow was fully analyzed with no untrusted checkouts, injection findings, or excessive top-level permissions. However, all 8 action references are unpinned, leaving avoidable build-integrity and reproducibility risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
behat/behat Version ^3.31 || ^4.0 | — | — |
symfony/http-kernel Version ^7.4 || ^8.0 | — | — |
symfony/dependency-injection Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.