Tests, a changelog, a license, and organization backing provide useful maintenance and transparency evidence. The release is still a prerelease, while recent repository activity has stalled and workflow references need pinning.
64%
Total Score
75
100
93
50
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although a release was published during the observed period, the lack of recent development activity is a maintenance concern.
The repository has no SECURITY.md or equivalent security policy. This is a transparency and reporting gap, although it is partly offset by the presence of Dependabot and Sonar scanning.
v1.0.0-rc.5 is a prerelease, and all recent releases are prereleases. That increases compatibility uncertainty for production consumers.
All 51 analyzed action references are unpinned, which weakens build reproducibility. The audit found high-confidence template-injection patterns, but no pull_request_target or workflow_run triggers and no untrusted checkout or script-injection sinks, so this remains a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/filesystem Version ^6.0 | — | — |
symfony/http-foundation Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.