The source repository includes tests and a clear README, while the package has no install-time scripts and a declared MIT license. Workflow auditing found no active injection or secret issues.
62%
Total Score
50
88
67
The repository recorded zero commits and zero active maintainers in the last three months, while its last push coincided with the initial release about five months ago. This is the strongest maintenance concern.
This is a young package with only one release, published about five months ago, so its maintenance track record is still limited.
The project uses Composer build tooling, but no security scanning tools were detected, leaving a modest transparency and hygiene gap.
The repository has no security policy, which makes vulnerability reporting less explicit for a package intended to run as a Composer plugin.
All 19 analyzed action references are unpinned, weakening build reproducibility. The audit found no injection, untrusted checkout, secret, or write-permission findings, which keeps this a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^6.0 || ^7.0 || ^8.0 | — | — |
composer/composer Version ^2.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.