The repository has tests and a clear MIT license, but its small audience and five unanswered pull requests provide little evidence of active support. Automated dependency updates are enabled, yet all 18 workflow actions are unpinned and no security policy is published.
42%
Total Score
50
86
67
The package has had no release in more than four years: its latest release was January 2022, with zero releases in the last 12 months. The four-release history shows an established start but not ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the long release gap and indicating little current maintenance capacity.
There are five open pull requests, with no new or merged pull requests in the last month. This suggests pending contribution or maintenance work is not being processed.
The repository has no published security policy, which weakens vulnerability-reporting transparency. This is a supporting hygiene concern rather than evidence that the package is unsafe.
The only workflow was fully analyzed with no dangerous sinks or audit findings, but all 18 action references are unpinned. That leaves build inputs less reproducible and more exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^4.4 || ^5.0 | — | — |
setono/tag-bag Version ^1.4 | — | — |
symfony/config Version ^4.4 || ^5.0 | — | — |
knplabs/knp-menu Version ^3.1 | — | — |
webmozart/assert Version ^1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.