Unpinned workflow actions and no security policy weaken release hygiene. MIT licensing, tests, and a matching organization-backed repository provide useful safeguards, but do not restore momentum.
57%
Total Score
67
90
50
The latest release was nearly four years ago, with no releases in the last 12 months. The long prior history and 22 total releases show maturity, but current release inactivity is a real maintenance concern.
The repository recorded no commits and no active maintainers in the last three months, despite having been pushed more recently than the last release. This indicates substantially slowed maintenance.
There were no new or closed issues or pull requests in the last month, while six issues and five pull requests remain open. This suggests limited recent project attention.
The repository has no security policy. This is a transparency gap for reporting and handling vulnerabilities, although it does not by itself show that the package is unsafe.
The sole workflow was fully analyzed and has no dangerous triggers or audit findings, but all three action references are unpinned. That leaves avoidable build-integrity exposure and weakens workflow hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^4.4.20 || ^5.4 || ^6.0 | — | — |
symfony/config Version ^4.4.20 || ^5.4 || ^6.0 | — | — |
symfony/console Version ^4.4.20 || ^5.4 || ^6.0 | — | — |
mybuilder/cronos Version ^3.0 || ^4.0 | — | — |
symfony/http-kernel Version ^4.4.20 || ^5.4 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.