The organization-backed repository includes tests and a changelog. Its workflows use three unpinned actions, and the project has neither a security policy nor security scanning.
61%
Total Score
83
100
88
67
The package has 42 releases, all within one day, and no later release over its 107-day lifetime. This shows intense initial publication but does not yet demonstrate an established release cadence.
The repository recorded zero commits and zero active maintainers over the last three months. That quiet period is concerning for a package that had a concentrated release burst, though it is not evidence of archival by itself.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning reduces maintenance and supply-chain visibility.
The repository has no security policy. This weakens transparency around vulnerability reporting and response expectations.
The single workflow was fully analyzed with no reported audit findings or unsafe triggers, but all three action references are unpinned. That leaves the workflow exposed to action changes over time.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.0 || ^7.0 | — | — |
symfony/config Version ^6.0 || ^7.0 | — | — |
symfony/console Version ^6.0 || ^7.0 | — | — |
symfony/http-kernel Version ^6.0 || ^7.0 | — | — |
symfony/polyfill-php80 Version ^1.22 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.