The package has a clear README, MIT licensing, repository tests, and read-only workflow permissions. It has no security policy or scanning, and all three workflow actions are unpinned.
60%
Total Score
75
86
67
This is a 189-day-old package with only one release, so there is not enough release history to establish mature maintenance or compatibility practices.
The repository recorded no commits and no active maintainers in the last three months. Although it was pushed more recently, the current activity gap leaves ongoing maintenance uncertain.
The project uses build tooling, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence of unsafe behavior by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The single workflow was fully analyzed, uses read-only permissions, and has no reported audit findings, but all three action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/polyfill-php83 Version ^1.33 | — | — |
symfony/polyfill-php84 Version ^1.33 | — | — |
symfony/polyfill-php85 Version ^1.33 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.