Clear licensing, documentation, and security contact information improve maintainability. The repository is young and has no commits in three months, while workflow audit findings add release-process hygiene concerns.
58%
Total Score
83
100
81
100
The package is only 207 days old and has four releases, so its long-term maintenance record is still limited. The releases are recent, but the short history warrants some caution.
The repository recorded zero commits and zero active maintainers over the past three months. For a young package, this is a significant warning about current maintenance capacity.
Composer is used for builds, but no security scanning tool was detected. This is a modest supply-chain hygiene gap rather than evidence of unsafe code.
Version 0.5.0 is not yet a stable-major release, indicating that compatibility and API changes may still occur despite the absence of prereleases.
All four workflows were analyzed, all 45 action references are pinned, and no untrusted checkout or script-injection paths were found. High-confidence template-injection findings and repeated ad hoc package installs still create workflow hygiene concerns; the low-confidence cache finding is minor.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.3 | — | — |
yosymfony/toml Version ^1.0 | — | — |
jarvis-brain/core Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.