Tests, release notes, a clear license, and security tooling make the package straightforward to evaluate. Maintenance has slowed, and every workflow action is unpinned, leaving meaningful hygiene concerns for a development tool.
67%
Total Score
94
100
The package has 18 releases since October 2020, but none in the last 12 months and the latest registry release was about 18 months ago. This indicates a real maintenance slowdown, though the long release history provides some maturity evidence.
All 18 analyzed action references are unpinned, which weakens build reproducibility. The audit found only low-confidence cache-poisoning patterns, with no untrusted checkout or script-injection sinks, so those findings remain hygiene concerns rather than severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mockery/mockery Version ^1.5.1 | — | — |
symfony/console Version ^6.0 || ^7.0 | — | — |
symfony/process Version ^6.0 || ^7.0 | — | — |
composer/composer Version ^2.7 | — | — |
symfony/filesystem Version ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.