Clear documentation, tests, release notes, and organizational ownership support dependable use. Recent repository activity is quiet, and the workflows use two unpinned actions; the missing security policy adds a smaller transparency gap.
68%
Total Score
75
100
50
There were no commits and no active maintainers in the last three months. This is a meaningful maintenance concern, although the recent release and release notes show the project has not been abandoned outright.
The repository has no security policy. That leaves vulnerability-reporting expectations unclear, though this is a transparency gap rather than evidence that the package is unsafe.
Both workflows were analyzed successfully and no audit findings or dangerous trigger-and-sink combinations were reported. However, both of the two action references are unpinned, leaving their build inputs less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^1.0 || ^2.0 || ^3.0 | — | — |
twig/twig Version ^2.9 || ^3.0 | — | — |
symfony/form Version ^7.4 || ^8.0 | — | — |
symfony/config Version ^7.4 || ^8.0 | — | — |
psr/simple-cache Version ^1.0 || ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.