Regular releases and an organization-owned repository provide useful continuity. No commits in the last three months, absent security policy, and high-confidence workflow injection findings leave meaningful maintenance and automation concerns.
58%
Total Score
67
100
50
The repository recorded zero commits and zero active maintainers in the last three months, a material sign of slowed development that is only partly offset by recent registry releases.
There were 23 open issues but no new or closed issues and no merged pull requests in the last month, reinforcing the lack of recent repository activity.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a project with substantial runtime functionality.
All 12 action references are unpinned, and the audit found two high-confidence template-injection findings in img-sizes.yml that may expand attacker-controlled input into code; no dangerous trigger or untrusted checkout was reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
lyrasoft/luna Version ^2.2 | — | — |
windwalker/di Version ^4.0 | — | — |
symfony/mailer Version ^6.0||^7.0||^8.0 | — | — |
windwalker/dom Version ^4.0 | — | — |
windwalker/orm Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.