The package includes a security policy, a usable README, and no install-time scripts. All six workflow actions are unpinned, and the prerelease-heavy history provides limited assurance for a stable dependency.
52%
Total Score
0
67
100
The package has 57 releases, but all were published about 13 months ago and there were no releases in the following 12 months. This suggests the release line may be stalled despite its initially active burst.
The repository recorded no commits and no active maintainers during the last three months. Combined with no registry releases in the last 12 months, this points to slowed maintenance.
The repository name matches the package, supporting the linkage, but the README does not mention the package name. The missing README reference is a minor transparency concern rather than evidence of an unrelated repository.
The assessed version is a prerelease, and 70% of recent releases are prereleases. That reduces confidence in compatibility and release maturity for consumers seeking a stable dependency.
All three workflows were analyzed with no dangerous sinks or audit findings, but all six action references are unpinned. Unpinned actions create avoidable build-integrity risk, while the lack of top-level permissions is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.0 | — | — |
symfony/config Version ^5.0 | — | — |
symfony/http-kernel Version ^5.0 | — | — |
symfony/dependency-injection Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.