The repository includes tests, release notes, and a clear MIT license, with organizational backing and no archival or deprecation signal. Its recent commit window is quiet, and the workflows have a high-confidence template-injection finding plus no pinned actions.
58%
Total Score
75
90
50
The package has had no registry release in the last 12 months, despite six releases since November 2023; the latest release was about 15 months ago. This indicates a meaningful maintenance slowdown.
The repository recorded zero commits and zero active maintainers in the last three months. That weakens evidence of ongoing maintenance, although the repository was pushed more recently than the release history suggests.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, partly offset by the repository's tests and established project structure.
All 8 analyzed action references are unpinned, and the audit found one high-confidence template-injection issue. The workflows have no untrusted checkouts or script-injection findings, so this is a hygiene concern rather than a severe dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0 | — | — |
mlocati/ocsp Version ^1.0 | — | — |
symfony/translation-contracts Version ^2.5 || ^3.0 | — | — |
rollerworks/pdb-symfony-bridge Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.