The repository is not archived and includes tests, a README, a security policy, and a clear MIT license. All 16 workflow references are unpinned, adding avoidable build-supply-chain risk.
18%
Total Score
0
60
83
Packagist marks the entire package as abandoned, with no distinct replacement identified. Package-level abandonment is a severe obstacle to safely adopting this release.
The package has 211 releases over roughly 11 years, but its latest release was in January 2022 and it had no releases in the last 12 months. The long release history shows prior maturity, but does not offset the current multi-year release gap.
The repository recorded no commits and no active maintainers during the last three months. This supports the abandonment concern, although the repository is not archived.
All 16 analyzed action references are unpinned, and two high-confidence findings identify unpinned container images. The audit found no untrusted checkouts or script injection, but the workflow supply chain still lacks useful pinning.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version ^5.4|^6.0 | — | — |
doctrine/orm Version ^2.10 | — | — |
symfony/form Version ^5.4|^6.0 | — | — |
symfony/intl Version ^5.4|^6.0 | — | — |
symfony/asset Version ^5.4|^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.