Usable with caveats: the package has a long release history, a matching organization-backed repository, tests, and recent releases. This specific beta release is far behind the current stable version, while repository activity has been inactive for nearly three months and workflow permissions are broadly unspecified.
65%
Total Score
67
93
67
There were no commits and no active maintainers in the three months before collection, which is a meaningful maintenance warning despite the recent registry releases and repository push date.
The repository has 73 open issues and 28 open pull requests, but no new or closed issues or merged pull requests in the last month, indicating a backlog without recent issue-management activity.
The repository has no security policy, leaving vulnerability reporting and response expectations less transparent for consumers.
Eight of nine workflows lack top-level token permissions and one workflow declares top-level write access; although no dangerous workflow patterns were detected, this is weaker permission hygiene than an explicitly least-privileged setup.
This release is explicitly a prerelease beta, while the package's latest version is stable 4.7.0, so adopting it means choosing an older, less stable line without evidence here that it remains the recommended version.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kherge/amend Version 1.* | — | — |
seld/jsonlint Version 1.* | — | — |
kherge/version Version 1.* | — | — |
symfony/finder Version 2.1.* | — | — |
symfony/console Version 2.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.