Tests, release notes, and organizational backing provide useful maintenance context. The missing security policy and unpinned workflow actions leave avoidable transparency and build-integrity gaps.
58%
Total Score
75
90
50
The package has had no release in over two years, despite 12 releases since April 2021; this materially raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and weakening maintenance confidence.
No security policy is present in the linked repository, leaving reporting and response expectations undocumented for a library used in application infrastructure.
The single analyzed workflow completed without detected dangerous findings, but all three action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version >=2.0 | — | — |
psr/http-message Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.