Tests, a matching repository, and a clear MIT license make the package easier to assess. Its automated build is complete, but all 19 workflow action references are unpinned.
43%
Total Score
50
80
50
The latest release was published in April 2022, with no releases in over four years and only three releases overall. This is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and providing no evidence of current maintenance.
The repository has no published security policy, leaving vulnerability reporting and handling expectations unclear. This is a transparency gap, though it is less severe than the maintenance evidence.
The single workflow was fully analyzed without untrusted checkouts, script injection, or audit findings. However, all 19 action references are unpinned, leaving avoidable build-reproducibility and action-substitution risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
twig/twig Version ^2.0 || ^3.0 | — | — |
payum/payum Version ^1.6 | — | — |
symfony/config Version ^4.4 || ^5.4 | — | — |
symfony/routing Version ^4.4 || ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.