The package includes tests, a changelog, a README, clear licensing, and a security policy. Its workflows are fully unpinned, which weakens build reproducibility despite no detected dangerous workflow findings.
58%
Total Score
50
100
89
100
The repository is owned by a user account rather than an organization, so there is no collected evidence of institutional backing. This makes the inactive recent commit record more concerning, though ownership alone is not a defect.
The repository recorded zero commits and zero active maintainers in the last three months. Although the package had a release on April 12, 2026, the recent absence of source activity is a meaningful maintenance concern.
The repository has two stars, no forks, and no watchers, providing little community evidence or external support. Popularity is only supporting evidence, so this modestly lowers confidence in long-term backing rather than deciding the verdict.
Composer is used for builds, but no security-scanning tool was detected. This is a hygiene gap, partially offset by the repository's published security policy.
All five workflows were analyzed with no dangerous sinks or audit findings, and none grants top-level write access. However, all 20 action references are unpinned, which weakens reproducibility and increases dependence on moving external references.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
symfony/form Version ^5.0 | — | — |
symfony/yaml Version ^5.0 | — | — |
symfony/asset Version ^5.1 | — | — |
symfony/cache Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.