The source includes a substantial test suite, clear documentation, organization backing, and Composer security scanning. Maintenance has been inactive for three months, releases were concentrated within about 14 hours, and all 12 workflow actions are unpinned.
61%
Total Score
75
86
75
The package has only three releases, all published within roughly 14 hours, followed by no newer release during its 210-day lifetime. That leaves limited evidence of sustained maintenance.
There were zero commits and zero active maintainers in the last three months. For a package only about seven months old, that is a meaningful maintenance and abandonment concern.
The repository has no published security policy. This is a transparency gap, though the available security scanning and organization backing provide some compensation.
Version v0.0.3 is not a stable major release, so its API may still change. The absence of recent prereleases avoids adding another instability concern.
The single workflow was fully analyzed with no untrusted checkout, injection, or high-severity findings, but all 12 action references are unpinned. The missing top-level permissions block is acceptable on its own, while unpinned references remain a supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 || ^4.0 | — | — |
symfony/config Version ^7.0 || ^8.0 | — | — |
symfony/routing Version ^7.0 || ^8.0 | — | — |
spatie/schema-org Version ^3.0 | — | — |
symfony/http-kernel Version ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.