The repository includes tests and publishes release notes, with MIT licensing and no install-time scripts. Organization backing and a non-archived repository provide some continuity, but this is not a low-maintenance dependency.
56%
Total Score
100
83
67
The package has six releases since May 2019 but none in the last 12 months; its latest registry release was in June 2024, indicating a prolonged maintenance gap.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented; this is a transparency gap, though not evidence of unsafe code.
The assessed release is v2.0.0-alpha, so consumers should expect unfinished or changing behavior despite the package having an established release history.
All 18 workflow action references are unpinned, creating reproducibility and action-substitution risk. The workflow has no untrusted checkout or script-injection findings, and its missing top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^5.4 || ^6.4 || ^7.0 | — | — |
symfony/http-kernel Version ^5.4 || ^6.4 || ^7.0 | — | — |
setono/post-nord-php-sdk Version ^2.0@alpha | — | — |
symfony/dependency-injection Version ^5.4 || ^6.4 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.