The project has a long release history, a matching organization-backed repository, clear licensing, tests, release notes, and reproducible build and security tooling. A missing security policy and workflow audit concerns add maintenance and hygiene caveats.
68%
Total Score
63
100
100
67
There were zero commits and zero active maintainers in the last three months, a meaningful sign that development activity has recently stalled despite the latest release and recent push.
No issues or pull requests were opened, closed, or merged in the last month, which adds evidence of limited current maintenance capacity.
No repository security policy was found, leaving reporting and response expectations undocumented. Existing security scanning helps, but does not replace a policy.
All six workflows were analyzed, all 51 action references are pinned, and no untrusted checkout or script-injection path was found. The high-confidence template-injection finding in the release workflow is a hygiene concern; the two low-confidence cache findings carry limited weight.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fidry/console Version ^0.6.10 | — | — |
symfony/finder Version ^6.4 || ^7.4 | — | — |
symfony/console Version ^6.4 || ^7.4 | — | — |
fidry/filesystem Version ^1.1 | — | — |
nikic/php-parser Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.