Documentation, licensing, and security guidance are in place. The project is too new to show a dependable maintenance record.
42%
Total Score
83
100
89
75
The audit found a high-confidence template-injection issue in coderabbit.yml, alongside an untrusted checkout in the same workflow_run-based workflow; all 18 action references are also unpinned. These are material CI supply-chain and reproducibility concerns despite complete audit coverage.
This package is less than a day old with only two releases, so there is not yet enough history to demonstrate sustained maintenance or release stability.
The repository shows zero commits and zero active maintainers in the last three months, but the package itself is brand new, so this is mainly an absence of maturity evidence rather than confirmed abandonment.
The repository has zero stars, forks, and watchers. For a package released less than a day ago, this is weak supporting evidence rather than a standalone health verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.4 || ^8.0 | — | — |
symfony/config Version ^7.4 || ^8.0 | — | — |
symfony/console Version ^7.4 || ^8.0 | — | — |
symfony/routing Version ^7.4 || ^8.0 | — | — |
symfony/http-kernel Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.