The package includes tests, a changelog, security scanning, and a clear repository match. The organization-backed project has recent activity, but current work is concentrated in one contributor and workflow references are not pinned.
72%
Total Score
67
100
100
67
One contributor made 100% of the four recent commits, creating a meaningful continuity risk despite the repository being owned by an organization that can potentially provide handoff capacity.
Four commits were made in the last three months, showing recent activity, but all activity came from only one active maintainer.
The repository has no security policy, leaving disclosure and response procedures undocumented; this is a transparency gap, though it is not evidence of unsafe code.
All four analyzed action references are unpinned, and the audit found one high-confidence medium-severity archived action. However, all workflows were analyzed, there are no untrusted checkouts or script injections, and no top-level write permissions.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/filesystem Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.