It has a long release history, a stable version, clear MIT licensing, tests, and release notes. Recent commit activity has stopped, while workflow references and container images are not pinned and no security policy is present.
64%
Total Score
67
93
75
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful recent maintenance warning despite the package's longer release history.
There were no new or closed issues or merged pull requests in the last month, although seven pull requests remain open. Combined with zero recent commits, this suggests currently quiet project activity.
The repository uses Composer and Make for builds, but no security-scanning tools were detected. The missing scanning is a hygiene weakness, not evidence of abandonment by itself.
No repository security policy was found. This reduces transparency for reporting and handling vulnerabilities, though it does not by itself make the release unfit.
All 33 action references are unpinned, and two high-confidence findings identify unpinned container images; one workflow also has top-level write permissions. The pull_request_target trigger has no untrusted checkout or script-injection sink, so it is not independently dangerous.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
twig/twig Version ^3.0 | — | — |
nyholm/psr7 Version ^1.4 | — | — |
symfony/form Version ^6.4 || ^7.3 || ^8.0 | — | — |
symfony/mime Version ^6.4 || ^7.3 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.