The package includes tests, a license, and a security policy, with no install scripts or deprecation. Organization backing partly offsets the single recent contributor; workflow actions should be pinned.
78%
Total Score
67
100
100
100
All recent commits came from one contributor. The organization-owned repository provides some maintenance capacity, but no second recently active contributor is shown.
Only two commits were recorded in the last three months, from one active maintainer, so recent source activity is thin despite the frequent release history.
Both workflows use read-only permissions, have no untrusted checkouts or injection findings, and the audit completed fully. However, all seven analyzed action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^5.4|^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.