The package has a mature repository, documented release notes, tests, and organization backing. Maintenance has gone quiet recently, while workflow dependencies are entirely unpinned and include archived actions; these weaken confidence in ongoing upkeep.
70%
Total Score
75
100
100
67
The repository had no commits and no active maintainers in the last three months. The recent release offsets this somewhat, but the lack of current development lowers confidence in ongoing maintenance.
There are six open issues and three open pull requests, but no issues or pull requests were created or merged in the last month. This suggests limited current activity, though it is not conclusive abandonment evidence.
No repository security policy was found. This is a transparency and vulnerability-reporting gap, although the repository does use composer-audit.
All 11 analyzed action references are unpinned, and two high-confidence medium-severity findings identify archived actions. The low-confidence cache-poisoning finding is hygiene only; no untrusted checkout or script-injection sink was found, so this is a caution rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^6.1 | — | — |
doctrine/dbal Version ^3.1 | — | — |
fakerphp/faker Version ^1.17 | — | — |
symfony/config Version ^6.1 | — | — |
symfony/finder Version ^6.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.