Its license, tests, changelog, and exact release notes make it transparent to maintain. The repository has had no commits or active maintainers in the last 3 months, and its workflow uses broad write access plus unpinned references.
60%
Total Score
67
100
94
75
There were 0 commits and 0 active maintainers in the last 3 months, which is a material maintenance and abandonment concern for a framework dependency.
Only one issue is open and there has been no new or closed issue or pull-request activity in the last month, offering little evidence of current maintenance.
Composer is used for builds, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, making vulnerability reporting and response expectations less clear.
All 13 analyzed action references are unpinned, and two high-confidence findings identify unpinned container images; the sole workflow also grants top-level write access, creating avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
php81_bc/strftime Version ^0.7.5 | — | — |
composer/ca-bundle Version ^1.5 | — | — |
symfony/polyfill-intl-icu Version ^1.29 | — | — |
symfony/polyfill-mbstring Version ^1.29 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.