Symfony FormType for ALTCHA — privacy-friendly, self-hosted proof-of-work CAPTCHA alternative for forms (GDPR-friendly, no cookies).
58%
Total Score
caution
A brand-new package has strong project hygiene but high-confidence GitHub Actions risks and all action references are unpinned.
All seven workflows were analyzed, but both high-confidence template-injection findings involve workflows with attacker-reachable automation, including an untrusted checkout in coderabbit.yml; all 22 action references are also unpinned. These create meaningful release and CI integrity risk.
The bundle declares 22 runtime dependencies, largely matching its Symfony integration scope, but the relatively broad dependency surface increases upgrade and compatibility exposure.
There are three releases in less than a day, showing active initial publishing but providing too little history to establish long-term maintenance reliability.
The repository reports zero commits and zero active maintainers in the last three months, but the package itself is less than a day old, so this mainly limits maturity evidence rather than proving abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
psr/cache Version ^1.0 || ^2.0 || ^3.0 | — | — |
psr/clock Version ^1.0 | — | — |
symfony/form Version ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/yaml Version ^6.0 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.