The codebase includes tests, a changelog, release notes, and an MIT license, while the dependency set is small. Its inactive maintenance and basic CI hygiene make future fixes and updates uncertain.
58%
Total Score
75
100
92
50
The latest release was about four and a half years ago, with no releases in the last 12 months. The nine-release history shows prior development but does not offset the prolonged inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push in March 2022. This materially raises maintenance and abandonment risk.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap, though it is less serious for this small package than evidence of active compromise would be.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all three referenced actions are unpinned. The missing top-level permissions block is acceptable on its own and is not paired with an untrusted trigger.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.