It has a clear MIT license, a long release history, and documented release notes for this version. Recent repository commits are absent, while workflow dependencies are broadly unpinned and include a high-confidence unpinned container image finding.
68%
Total Score
67
94
100
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful sign of slowed maintenance; the recent release and May push provide only partial compensation.
There are no open issues and one open pull request, but there was no new or merged pull-request activity in the last month, offering limited evidence of active development.
The repository uses Composer and Make, but no security scanning tools were detected, leaving a modest repository-hygiene gap.
All 21 analyzed action references are unpinned, and the audit found a high-confidence unpinned container image; the pull_request_target workflow has no untrusted checkout or script-injection sink, limiting this to a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
symfony/intl Version ^6.4 || ^7.3 || ^8.0 | — | — |
symfony/config Version ^6.4 || ^7.3 || ^8.0 | — | — |
symfony/http-kernel Version ^6.4 || ^7.3 || ^8.0 | — | — |
symfony/http-foundation Version ^6.4 || ^7.3 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.