The project has a clear README, tests in the repository, stable releases, and recent GitHub publishing. Commit activity was absent in the last three months, while workflow actions are unpinned and no security policy is provided.
78%
Total Score
83
100
100
83
No commits and no active maintainers were recorded during the last three months, which weakens evidence of current development despite the recent release and repository push.
The repository has no security policy, leaving disclosure and response procedures undocumented; this is a modest transparency gap for a dependency.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, injections, or audit findings. However, both action references are unpinned, which is a workflow supply-chain hygiene gap, while the absence of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/notifier Version ^6.0 || ^7.0 || ^8.0 | — | — |
job-runner/job-runner Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.