The repository is actively maintained by three contributors and the package includes documentation, tests in source, and release notes. All six workflow actions are unpinned, and no security policy is provided.
79%
Total Score
100
81
75
Only two releases have been published over 228 days, with a median interval of about 83 days. This is limited release history, though repository activity provides compensating evidence of ongoing work.
Composer build tooling is present, but no security-scanning tool was detected; this is a modest transparency and hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Version v0.7.1 is not a stable major release, so the API may still change; it is not a prerelease, which partly reduces that concern.
Both workflows use read-only permissions, have no untrusted checkout or script-injection findings, and the audit completed fully. However, all six action references are unpinned, creating a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
symfony/config Version ^6.4 || ^7.4 | — | — |
pimcore/pimcore Version ^11.5 || ^12.0 | — | — |
symfony/contracts Version ^2.5 || ^3.5 | — | — |
symfony/messenger Version ^6.4 || ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.