All workflow action references are unpinned, and one uses an archived action. The repository has no security policy, though it has tests, a README, and security scanning tools.
60%
Total Score
75
94
50
Composer post-install and post-update scripts run during dependency operations, adding supply-chain and installation complexity that developers should account for.
The package has 38 releases since July 2020, but none in the last 12 months; this is meaningful evidence of slowing maintenance for a dependency.
There were no commits from any active maintainer in the last three months, which is a direct maintenance concern despite the repository's recent push timestamp.
No repository security policy is provided, reducing transparency about vulnerability reporting and response expectations.
All 29 analyzed action references are unpinned, and the audit found one high-confidence medium-severity use of an archived action. No untrusted checkout, script injection, or broad top-level write permissions were found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.5 || ^3.0 | — | — |
symfony/yaml Version ~4.4|~5.4|~6.0|~7.0 | — | — |
aws/aws-sdk-php Version ^3.39.0 | — | — |
doctrine/common Version ^2.4 || ^3.0 | — | — |
symfony/http-kernel Version ~4.4|~5.4|~6.0|~7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.