Tests, release notes, licensing, and static analysis provide useful project structure. Maintenance has slowed substantially, and all seven workflow actions are unpinned, leaving meaningful upkeep and build-integrity concerns.
58%
Total Score
50
93
75
Only one registry publishing account is listed. As the repository is owned by an individual rather than an organization, this indicates a thin maintainer base and limited continuity if that maintainer steps away.
The package has had no releases in the last 12 months, with the latest release roughly 22 months ago. Its five releases were initially frequent, but the long current gap lowers confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months. The repository is not archived, but this recent inactivity supports a maintenance concern.
All seven analyzed action references are unpinned, which weakens build reproducibility and exposes workflows to moving dependencies. The audit found no injection sinks or high-severity findings, so this is a hygiene caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^v6.4 | — | — |
symfony/console Version ^v6.4 | — | — |
symfony/process Version ^7.1 | — | — |
nikic/php-parser Version ^v4.19 | — | — |
symfony/filesystem Version ^v6.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.