Clear documentation, licensing, and a stable release history support adoption. Recent repository activity is absent, while all five workflow actions are unpinned and a high-confidence workflow condition is always true. Treat maintenance and CI hygiene as meaningful caveats.
62%
Total Score
67
100
75
The repository recorded zero commits and zero active maintainers in the last three months, which is a concrete sign of slowed maintenance for a current release line.
There were no new or closed issues or pull requests in the last month, while three issues and two pull requests remain open; this suggests limited recent project response.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented; this is a transparency gap, though dependency scanning provides some compensating security practice.
The single workflow was fully analyzed, but all five action references are unpinned and a high-confidence audit found a condition that always evaluates to true. No untrusted checkout, injection, or broad top-level write permission was detected, so this is a hygiene and reliability concern rather than a severe supply-chain finding.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.6 | — | — |
symfony/config Version ^5.4 || ^6.4 || ^7.4 | — | — |
symfony/routing Version ^5.4 || ^6.4 || ^7.4 | — | — |
contao/core-bundle Version ^4.13 || ^5.3 | — | — |
symfony/http-kernel Version ^5.4 || ^6.4 || ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.