Clear documentation, tests, release notes, and licensing support adoption. The small contributor base and unpinned workflow actions deserve attention, but there is no sign of abandonment.
78%
Total Score
75
100
100
75
The registry and repository are owned by the same individual account, so the package identity is clear, but there is no organization backing to offset the concentrated contributor activity.
Two contributors were active, but the leading contributor made about 83% of recent commits, leaving maintenance meaningfully concentrated.
The repository has no security policy, which leaves vulnerability reporting and response expectations undocumented.
Both workflows were analyzed successfully with no reported audit findings or untrusted checkout and script-injection paths. However, all nine action references are unpinned and one workflow grants top-level write permissions, creating workflow hygiene and change-control concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || 2.0 || ^3.0 | — | — |
doctrine/dbal Version ^3.6 || ^4.0 | — | — |
symfony/config Version ^6.0 || ^7.0 | — | — |
symfony/console Version ^6.0 || ^7.0 | — | — |
symfony/routing Version ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.