The project ships frequently, includes tests and release notes, and has a license and security policy. Its small contributor base and broad dependency set add ongoing maintenance risk.
68%
Total Score
75
50
100
100
The release declares 53 runtime dependencies and numerous platform extensions, making upgrades and compatibility management materially more complex than for a small package.
The repository owner is an individual rather than an organization, so the small contributor base and concentrated commit share represent a real handoff risk.
Two contributors were active in the last three months, but one made about 87% of commits, leaving maintenance concentrated in one person.
All four workflows were analyzed and have no untrusted checkout or script-injection counts, but all eight action references are unpinned. The audit also reports one high-confidence template-injection finding in staging-deploy.yml, which is a meaningful workflow hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.20 | — | — |
symfony/uid Version ^8.1 | — | — |
symfony/flex Version ^1.17|^2 | — | — |
symfony/form Version ^8.1 | — | — |
symfony/intl Version ^8.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.