The project has tests, a clear GPL license, and an organization-owned repository. Its single workflow uses four unpinned actions, and the repository has no security policy or security scanning, limiting supply-chain hygiene.
67%
Total Score
75
50
81
75
The package declares nine runtime dependencies, including Composer and several Symfony components. This is a substantial dependency surface, but no specific problematic dependency pattern is shown.
The latest registry release was 22 September 2023, with no releases in the following 12 months. The linked repository was pushed recently, but registry delivery has clearly stalled.
There were no commits and no active maintainers in the three months measured. Although the recent push date is reassuring, the absence of recent commit activity weakens confidence in ongoing maintenance.
The repository has seven open issues, no issues closed in the last month, and one new pull request without a merge. This suggests limited recent project follow-through.
Composer is used for the build, which supports reproducible project management, but no security scanning tools are reported. That leaves a modest supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^3.0|^4.0|^5.0 | — | — |
symfony/finder Version ^3.0|^4.0|^5.0 | — | — |
gitonomy/gitlib Version 0.1.*@dev | — | — |
symfony/console Version ^3.0|^4.0|^5.0 | — | — |
symfony/process Version ^3.0|^4.0|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.