This release appears generally healthy and reasonable to adopt: it is actively developed, not deprecated or archived, has a stable major version, clear MIT licensing, documentation, tests, changelog, security policy, dependency automation, and a repository that references the package. The main concerns are the very young project age, unusually frequent releases, zero observed popularity, and strong concentration of recent commits in one human contributor, although organization ownership and a second active contributor partially mitigate the bus-factor risk. CI workflow permissions and untrusted workflow usage also deserve review before relying on the repository as a high-assurance supply-chain dependency.
82%
Total Score
90
100
89
80
Seven workflows were analyzed; one uses pull_request_target and one performs an untrusted checkout in a workflow_run context. No script-injection patterns were detected, but these workflow patterns warrant review because they can increase CI supply-chain exposure.
The package is only 45 days old but has 40 releases, with a median interval of about 1 hour. This demonstrates active publishing, but the short history and unusually rapid cadence leave long-term stability less established.
One contributor made 55 of 59 recent commits, or about 93%, which creates a meaningful concentration risk. The organization-owned repository and a second active contributor partially compensate, so this is caution rather than danger.
The repository has zero stars, forks, and watchers. Given the package is only 45 days old, this is limited supporting evidence rather than a decisive abandonment concern, but external adoption is not yet demonstrated.
Five workflows lack top-level permissions and two declare top-level write access, with no workflows showing read-only permissions. This is weaker least-privilege hygiene and merits review, although it does not establish that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
psr/clock Version ^1.0 | — | — |
symfony/config Version ^7.0 || ^8.0 | — | — |
symfony/http-client Version ^7.0 || ^8.0 | — | — |
symfony/http-kernel Version ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.