Clear documentation, licensing, and release notes make integration straightforward. Dependabot and read-only workflow permissions add useful safeguards, while the organization provides some continuity despite a narrow recent activity base.
72%
Total Score
67
100
100
75
All seven recent commits came from one contributor, creating a concentrated short-term bus factor. Organization ownership provides some handoff capacity but does not remove the concentration concern.
Seven commits occurred in the last three months, showing current activity, but only one active maintainer contributed them, limiting visible maintenance capacity.
The repository has no published security policy, leaving vulnerability-reporting guidance less transparent for users and maintainers.
The single workflow was fully analyzed, uses read-only permissions, and has no dangerous audit findings. However, both analyzed action references are unpinned, weakening build reproducibility and action supply-chain controls.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.15.3 || ^3.4.3 | — | — |
symfony/form Version ^5.4 || ^6.4 || ^7.0 | — | — |
symfony/config Version ^5.4 || ^6.4 || ^7.0 | — | — |
symfony/validator Version ^5.4 || ^6.4 || ^7.0 | — | — |
symfony/http-kernel Version ^5.4 || ^6.4 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.