The project is actively maintained and documented, with tests and recent release notes. Its workflow hygiene and lack of a security policy leave avoidable maintenance and supply-chain concerns.
68%
Total Score
100
88
63
post-install-cmd and post-update-cmd scripts run during dependency operations, adding execution and review risk compared with a package without install-time behavior.
Composer build tooling is present, but no security-scanning tool was detected in the repository, leaving a modest assurance gap.
The repository has no SECURITY.md or other detected security policy, reducing transparency about vulnerability reporting and response.
Version 0.3.8 is not a prerelease and recent prereleases account for none of the recent versions, but the unreleased major version signals less API maturity than a stable 1.x package.
All 8 analyzed action references are unpinned, and the audit found a high-confidence template-injection issue in trigger-remote-pr.yml. No untrusted checkout or script-injection sink was reported, so the template issue is a workflow-hygiene concern rather than a severe standalone verdict.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/uid Version ^6.0 || ^7.0 | — | — |
symfony/flex Version ^1.17|^2 | — | — |
symfony/yaml Version ^6.0 || ^7.0 | — | — |
symfony/dotenv Version ^6.0 || ^7.0 | — | — |
composer/semver Version ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.