Recent releases and a complete source repository provide useful continuity, while commit activity has been absent for 3 months. All six workflow actions are unpinned and the repository has no security policy, leaving meaningful maintenance and workflow-hygiene concerns.
72%
Total Score
75
50
100
83
Sixteen runtime dependencies create a relatively broad dependency surface for this package, increasing maintenance and transitive-change exposure, though the dependencies are declared transparently.
The repository recorded zero commits and zero active maintainers in the last 3 months, a concrete sign that maintenance may have stalled despite the recent release.
No repository security policy is present, leaving vulnerability reporting and response expectations undocumented.
All three workflows were analyzed successfully with no detected injection or dangerous-trigger findings, but all 6 action references are unpinned, so workflow dependencies can change without a reviewed version.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/uri Version ^7.0 | — | — |
veewee/xml Version ^4.9 | — | — |
php-soap/xml Version ^1.9 | — | — |
symfony/console Version ^5.4 || ^6.0 || ^7.0 || ^8.0 | — | — |
league/uri-components Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.