The workflows leave all seven action references unpinned, and the repository has no security policy. Licensing, tests, release notes, and a matching README provide useful transparency.
58%
Total Score
0
81
75
The package has had no registry release in over five years, despite a mature five-release history, which raises abandonment risk.
There were no commits and no active maintainers in the last three months, a concrete sign that maintenance may have stalled.
Composer build tooling is present, but no security-scanning tooling was detected, leaving release-integrity checks less transparent.
The repository has no published security policy, reducing clarity about vulnerability reporting and maintainer response.
All seven analyzed action references are unpinned, and a high-confidence archived-action finding appears in the release workflow. The cache-poisoning findings are low confidence and do not materially add risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sebastian/diff Version ^4.0 | — | — |
symfony/process Version ^5.1 | — | — |
symfony/filesystem Version ^5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.