Tests, documentation, licensing, and organizational backing provide a solid foundation. However, no commits or releases have appeared for over a year, and the workflow uses an unpinned container image.
58%
Total Score
75
100
94
83
The package has 16 releases over about two years, but it has had no registry release in the last 12 months, which suggests maintenance has stalled.
There were no commits and no active maintainers in the last three months, consistent with the broader absence of recent releases and indicating a real maintenance concern.
All three analyzed action references are unpinned, and the audit found a high-confidence workflow using a floating latest container image. No dangerous triggers, untrusted checkouts, or script-injection sinks were found, so this is a hygiene caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
thecodingmachine/safe Version ^3.0 | — | — |
symfony/http-foundation Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.