The package has clear documentation, repository tests, release notes, and a source repository that matches the package. One publisher and only two recent commits limit maintenance redundancy, despite two active contributors.
70%
Total Score
75
100
50
The package runs both post-install-cmd and post-update-cmd scripts, so installation and updates execute package-defined code. That is a meaningful supply-chain consideration even though no malware finding is present.
Only two commits were recorded in the last three months, which is limited activity for a package with frequent releases. Two active maintainers and the recent repository push partly offset abandonment concerns.
The linked repository has no security policy, reducing transparency about vulnerability reporting and response. Dependabot and other repository evidence provide some compensating security practice, so this is a minor concern rather than a severe risk.
All 17 analyzed action references are unpinned, allowing workflow dependencies to change without a repository change; however, all five workflows were audited, four use read-only permissions, and no dangerous sinks or audit findings were reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^7.0||^8.0 | — | — |
symfony/process Version ^7.0||^8.0 | — | — |
sandermuller/boost-core Version ^1.0 | — | — |
stolt/lean-package-validator Version ^5.7||^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.