The package is small and clearly documented, with repository tests and a matching source repository. Its maintenance has effectively stopped, and the workflow uses unpinned actions, which increases long-term dependency risk.
55%
Total Score
50
83
50
This package has only one release, published about four years ago, with no releases in the last 12 months. That limits evidence of ongoing maintenance, although a stable utility can remain unchanged after a complete initial release.
The repository recorded no commits and no active maintainers in the last three months, consistent with the last push occurring about four years ago. The repository is not archived, but there is little evidence of current maintenance.
Composer is used as the build tool, showing basic project tooling. No security scanning tools were detected, which is a modest hygiene gap rather than evidence that the release is unsafe.
The repository has no security policy, reducing the transparency of vulnerability reporting and response. This is a secondary concern because the package has a clear license and a small, directly inspectable file tree.
The workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both analyzed action references are unpinned, leaving them exposed to upstream changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^4.0|^5.0|^6.0 | — | — |
symfony/process Version ^4.2|^5.0|^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.