It has a clear license, extensive tests, and a documented security policy. Its release history is active, but low repository activity and weak workflow pinning leave maintenance and build reproducibility concerns.
61%
Total Score
50
89
100
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful sign of stalled maintenance that is only partly offset by the recent release history.
The repository has only 2 stars, 0 forks, and 0 watchers. This is weak supporting evidence, but popularity alone does not outweigh the stronger maintenance signals.
Composer is used for the build, but no security scanning tools were detected, leaving a modest repository hygiene gap.
All six workflows were analyzed without high- or medium-severity findings and the pull_request_target workflow has no untrusted checkout or script-injection sink. However, all 11 action references are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
mck89/peast Version ^1.9 | — | — |
symfony/form Version ^5.0 | — | — |
symfony/yaml Version ^5.0 | — | — |
symfony/asset Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.