The package includes tests, a changelog, release notes, and a matching license. Its workflow leaves all three actions unpinned and the repository has no security policy, so supply-chain hygiene is weaker.
78%
Total Score
75
90
67
The package has existed for about 3 years and 10 months but has only four releases, indicating a small release history; however, version 0.3.0 was published recently.
There are no new issues or merged pull requests in the last month, with one pull request still open; this is a minor activity concern, tempered by the recent release and push.
The linked repository has no security policy, leaving vulnerability-reporting expectations undocumented for a package used in Magento projects.
The only workflow was fully analyzed and has no dangerous triggers, untrusted checkouts, script injection, or audit findings, but all 3 of its action references are unpinned.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^4.4 || ^5.4 || ^6.0 | — | — |
symfony/console Version ^4.4 || ^5.4 || ^6.0 | — | — |
composer/composer Version ^2.2 | — | — |
magento/framework Version ~103.0.0 | — | — |
symfony/polyfill-php80 Version ^1.24 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.