The repository is compact, documented, licensed, and backed by an organization. Workflow references are all unpinned, and the audit found a high-confidence template-injection issue; recent registry releases and commits are also absent.
63%
Total Score
83
100
88
83
The package has only four releases over about 12 years and no registry release in the last two years and ten months, which indicates a very slow release cadence.
The repository recorded zero commits and zero active maintainers in the last three months, which is a concrete sign of currently inactive development.
The project uses Composer and Make, but no security scanning tools were detected, leaving a modest repository hygiene gap.
The repository has no security policy, making the reporting and handling process for vulnerabilities less transparent.
All 8 analyzed action references are unpinned, and the audit found a high-confidence template-injection issue in phpstan.yaml; there were no untrusted checkouts or script-injection findings, so this is workflow hygiene risk rather than a severe release blocker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/polyfill-mbstring Version ^1.28 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.