Regular releases and recent work from four contributors reduce abandonment concerns. The repository has tests, release notes, security reporting, and dependency scanning; workflow references remain unpinned and need cleanup.
88%
Total Score
100
100
100
100
All seven workflows were analyzed, with no untrusted checkouts or script-injection findings, but all 14 action references are unpinned and the audit found high-confidence template-injection hygiene issues in ci-perf.yml; without dangerous triggers, this is a caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-di/php-di Version ^7.1 | — | — |
psr/container Version ^2.0 | — | — |
respect/stringifier Version ^3.0 | — | — |
respect/string-formatter Version ^1.7 | — | — |
symfony/polyfill-intl-idn Version ^1.33 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.