The package has a useful README, tests, a matching source repository, and a clear GPL license. Its workflow uses read-only permissions but leaves both action references unpinned and the repository has no security policy.
43%
Total Score
0
79
75
The package has made no release in nearly four years; six releases arrived during its first few days, followed by prolonged silence. This is strong evidence of abandonment risk despite the stable 1.0.5 version.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no recent maintenance capacity.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide no meaningful community signal to offset the maintenance gap.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a transparency gap, though it is less serious than the lack of recent maintenance.
The only workflow is fully analyzed, uses read-only permissions, and has no audit findings, but both of its two action references are unpinned. That leaves avoidable build-integrity exposure without evidence of an active exploit path.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pestphp/pest Version ^1.22 | — | — |
symfony/cache Version ^6.0 | — | — |
symfony/string Version ^5|^6.1 | — | — |
symfony/validator Version ^5|^6.1 | — | — |
doctrine/annotations Version ^1.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.