The package is licensed, documented, tested in its repository, and has a long release history. Maintenance has paused recently, while all eight workflow actions are unpinned and a high-confidence template-injection finding remains.
62%
Total Score
75
100
88
25
All four workflows were analyzed with no untrusted checkout or script-injection trigger, but all 8 action uses are unpinned and a high-confidence template-injection finding was reported in phpstan.yaml. These workflow weaknesses materially reduce supply-chain hygiene.
There were no commits and no active maintainers in the last 3 months, a meaningful maintenance concern, though the recent registry releases and long release history provide some compensating evidence.
The project uses Composer and Make, but no security scanning tools were detected, leaving repository security hygiene less mature.
The repository has no security policy, which weakens vulnerability-reporting transparency for a package that validates passwords.
The assessed release is not marked as a prerelease and recent prereleases represent only 20% of releases, supporting stability, although the reported latest version is older than the assessed release and creates some version-data ambiguity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^7.4 || ^8.0 | — | — |
symfony/validator Version ^7.4 || ^8.0 | — | — |
symfony/translation Version ^7.4 || ^8.0 | — | — |
symfony/polyfill-mbstring Version ^1.5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.