The source includes tests, a changelog, a matching README, and an MIT license, while the repository is still available. Its workflows use unpinned container images, adding avoidable build-integrity risk.
45%
Total Score
0
86
50
Only two releases were published, both in June 2023, with no releases in the last 12 months; this is strong evidence of a stale package.
The repository recorded zero commits and zero active maintainers in the last three months, with no recent development activity to offset the old release history.
No security policy is present in the repository, reducing the project's transparency for reporting and handling security issues; the small, inactive project does not provide compensating evidence.
Both workflows were analyzed successfully and have no untrusted checkout or script-injection findings, but all four action references are unpinned and a high-confidence audit flagged an unpinned container image.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.2 | ^6 | — | — |
symfony/finder Version ^6.2 | — | — |
symfony/console Version ^5 | ^6 | — | — |
symfony/process Version ^5.4 | ^6 | — | — |
clue/stdio-react Version ^2.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.