Common functionality shared across MatesOfMate extensions
78%
Total Score
70
100
83
70
One workflow uses pull_request_target, a workflow form that requires careful handling of untrusted pull-request content. No untrusted checkout or script injection was detected, which materially limits the concern.
Only one account has registry publish access. Because the source repository is organization-owned, this is ordinary publishing hygiene rather than decisive evidence of weak project backing, but it still leaves release operations concentrated.
All seven recent commits came from one contributor, giving the repository a high bus-factor risk. Organization backing partially compensates for this, but no second active contributor is shown.
There are no open issues or pull requests and no recent issue or pull-request activity. This is not inherently negative for a small package, but it provides little evidence of community review or usage.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, so this lowers external validation but does not by itself make a small, active package unhealthy.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^5.4|^6.4|^7.3|^8.0 | — | — |
symfony/process Version ^5.4|^6.4|^7.3|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.