The bundle has a clear README, tests, release notes, an MIT declaration, and no install-time scripts. Its small maintainer base, no commits in three months, and fully unpinned workflow references warrant caution for long-term use.
67%
Total Score
50
100
94
67
Only one registry account has publish access. The linked repository is user-owned rather than organization-backed, so the narrow publisher base leaves limited visible continuity capacity.
The package has existed since 2018 with nine releases, but it had no releases in the last 12 months; this suggests slowing maintenance rather than abandonment on its own.
The repository recorded zero commits and zero active maintainers in the last three months. That is a meaningful maintenance warning, despite the repository not being archived.
No repository security policy was found. This is a transparency gap, but it is not severe enough by itself to outweigh the package's other evidence.
All three analyzed action references are unpinned, which weakens build reproducibility. The reported cache-poisoning finding has low confidence and is hygiene at most; the audit otherwise analyzed the single workflow completely.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^6.4|^7.2 | — | — |
symfony/validator Version ^6.4|^7.2 | — | — |
symfony/http-kernel Version ^6.4|^7.2 | — | — |
prometee/vies-client Version ^1.0 | — | — |
symfony/dependency-injection Version ^6.4|^7.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.