MIT licensing, repository tests, and a long release history provide useful support. The repository has no security policy or scanning, and its zero-star, zero-fork footprint offers little independent backing.
58%
Total Score
75
88
75
The repository recorded zero commits and zero active maintainers in the last 3 months, which weakens evidence of current maintenance despite the recent release history.
The repository has zero stars, forks, and watchers, providing little external evidence of adoption or community support. Organization backing and the package's long release history partly compensate, but not fully.
Composer and Box are used for the build, which is positive, but no security-scanning tools were detected. That leaves a meaningful repository hygiene gap.
The repository has no security policy, so consumers have no documented vulnerability-reporting process. This is a transparency gap, though it does not by itself make the release unfit.
All 15 analyzed action references are unpinned, and two workflows use high-confidence unpinned container images, including a floating latest tag. The audit completed fully and found no untrusted checkout or script-injection path, but the release automation remains exposed to mutable build inputs.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1.3 || ^2 || ^3 | — | — |
doctrine/dbal Version ^3.6 || ^4 | — | — |
symfony/console Version ^5.4 || ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/stopwatch Version ^5.4 || ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/var-exporter Version ^6.2 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.