The repository still has a recent release, two active contributors, and documented release notes. Packagist marks the package abandoned, so avoid adding this dependency to new projects.
38%
Total Score
100
75
50
Packagist marks the entire package as abandoned, with no replacement listed. This is a major maintenance and adoption risk despite the recent release activity.
The package has 9 releases over about 5 years, with only 1 release in the last 12 months and a roughly 364-day median interval. The latest release is recent, but the long cadence suggests limited ongoing development.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities in a security-focused package.
All three workflow action references are unpinned, which weakens build reproducibility. The audit found no untrusted checkouts, script injection, dangerous triggers, or high-confidence findings.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^4.0.0 || ^5.0.0 || ^6.0.0 || ^7.0.0 | — | — |
symfony/process Version ^4.0.0 || ^5.0.0 || ^6.0.0 || ^7.0.0 | — | — |
symfony/options-resolver Version ^4.0.0 || ^5.0.0 || ^6.0.0 || ^7.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.