The repository has tests, release notes for this version, an MIT license, and organization backing. A missing security policy and workflow hygiene issues add some maintenance and transparency risk.
67%
Total Score
83
100
94
75
The package has existed for about 4 years and released 15 versions, but only one release appeared in the last 12 months, indicating a slower cadence.
There were no commits and no active maintainers in the last three months. The recent release and two merged pull requests provide some evidence of activity, but do not fully offset the current inactivity.
The repository has no security policy, leaving vulnerability reporting and coordinated disclosure guidance unclear.
All 25 analyzed action references are unpinned, creating avoidable workflow supply-chain drift; the high-confidence template-injection finding is a further hygiene concern, although no untrusted checkout or script-injection sink was found.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.14 || ^3.4 | — | — |
symfony/config Version ^6.4 || ^7.4 || ^8.0 | — | — |
symfony/http-kernel Version ^6.4 || ^7.4 || ^8.0 | — | — |
symfony/http-foundation Version ^6.4 || ^7.4 || ^8.0 | — | — |
symfony/dependency-injection Version ^6.4 || ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.