The project has organizational backing, a complete README, tests, and a matching Apache-2.0 license. Recent development is thin, with one commit from one contributor in three months, while workflow references are entirely unpinned and include a high-confidence template-injection warning.
63%
Total Score
75
100
81
67
The package has existed since May 2016 with 34 releases, but it has had no registry release in the last 12 months, indicating slowed release activity.
All one recent commit came from a single contributor, but organization ownership provides some capacity to hand maintenance to others.
Only one commit was recorded in the last three months, showing limited recent implementation activity and increasing the risk of slow maintenance.
The repository uses Composer, but no security-scanning tooling was detected, leaving a security-process gap for a package that runs cloud and deployment utilities.
No repository security policy was found, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ~3.0 | — | — |
symfony/yaml Version ^5.0 || ^6.4 || ^7.0 | — | — |
symfony/console Version ^5.0 || ^6.4 || ^7.0 | — | — |
symfony/process Version ^5.0 || ^6.4 || ^7.0 | — | — |
guzzlehttp/guzzle Version ~7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.