The MIT license, included tests, and release notes provide useful transparency for adopters. Unpinned workflow actions and the lack of a security policy leave avoidable maintenance and supply-chain hygiene gaps.
55%
Total Score
0
63
50
The package has 71 releases since 2015, but it has had no release in roughly six years; that strongly raises abandonment and compatibility risk.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release pause and weakening evidence of ongoing maintenance.
The repository is not archived, which is a modest positive, but its last push was in July 2020 and does not offset the absent recent activity.
No security policy was found in the linked repository, reducing transparency about vulnerability reporting and response for a package that may still be used in production builds.
The single workflow was fully analyzed with no untrusted checkout, injection, or high-confidence audit findings, but all 3 action references are unpinned, leaving a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^4.0|^5.0 | — | — |
illuminate/view Version ^7.0 | — | — |
mockery/mockery Version ^1.0.0 | — | — |
symfony/console Version ^4.0|^5.0 | — | — |
symfony/process Version ^4.0|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.