Documentation, tests, and two active contributors provide a solid starting point. All workflow actions are unpinned and the repository lacks a security policy, so prefer a later established release when available.
70%
Total Score
83
100
93
67
The repository is owned by the individual user jpmmartin rather than an organization, so the small two-person contributor base represents the project's actual visible maintenance capacity.
The package is only 1 day old with two releases, so its maintenance pattern and compatibility over time are not yet demonstrated. The 158 recent repository commits provide useful activity but cannot replace a longer release history.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented. Composer auditing partly compensates for this operational gap but does not replace a policy.
Both workflows were analyzed successfully with no untrusted checkouts or script injection, and the cache-poisoning findings are low-confidence hygiene warnings. However, all 13 action references are unpinned, which weakens build reproducibility and supply-chain integrity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/lock Version ^6.4 || ^7.4 | — | — |
sylius/sylius Version ^2.2.6 | — | — |
paragonie/halite Version ^5.0 | — | — |
league/flysystem-bundle Version ^3.3 | — | — |
shipstream/fedex-rest-sdk Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.