Clear licensing, release notes, and a matching repository improve confidence. Unpinned workflow actions and no security policy leave maintenance safeguards weaker.
70%
Total Score
88
100
94
75
Only one registry publishing maintainer is listed, which limits publishing redundancy, though repository activity shows more than one recent contributor.
The package has existed for over 11 years with 18 releases, but it has had no registry release in the last 12 months; this is a meaningful freshness concern.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all four action references are unpinned, which weakens build reproducibility and action integrity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ~5.4|~6.4|~7.0 | — | — |
symfony/console Version ~5.4|~6.4|~7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.