The project has a clear consumer README, tests, and release notes, with a second contributor active recently. The workflow audit found no dangerous findings, though all four actions are unpinned and the repository has no security policy or scanning tool.
86%
Total Score
100
100
94
83
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest hygiene limitation, not evidence of abandonment.
The repository has no security policy. This lowers disclosure transparency somewhat, although the active repository and regular releases provide compensating maintenance evidence.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injections, or audit findings. However, all four action references are unpinned, creating a limited reproducibility and action-supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/process Version ~5|~6 | — | — |
composer/installers Version ~1.0|~2 | — | — |
mwstake/mediawiki-componentloader Version ~1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.