Tests, a clear MIT license, and dependency scanning provide useful project hygiene. The small repository and permissive workflow setup leave limited evidence of ongoing maintenance, so pinning this version is prudent.
58%
Total Score
75
100
94
75
The package has four releases since April 2022, but none in the last 12 months and the latest release is over a year old at collection time. This is meaningful evidence of slowing maintenance, though the stable release history provides some maturity.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the stale release cadence, this lowers confidence in active maintenance.
No security policy is present in the repository. This is a modest transparency gap, but it is not evidence that the package is unsafe on its own.
Both analyzed action references are unpinned, which weakens build reproducibility. The high-confidence template-injection finding is a workflow hygiene concern, but there is no untrusted checkout or script-injection sink to make it a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.3 | — | — |
symfony/cache Version ^5.4 || ^6.4 | — | — |
doctrine/annotations Version ^1.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.