Its small audience and single registry publisher limit resilience. Licensing, packaging, and repository linkage are clear, but recent repository inactivity, absent security scanning, and unpinned workflow actions warrant pinning this version.
66%
Total Score
83
100
89
75
There were no commits and no active maintainers in the last three months. Although the latest registry release is recent, this weakens evidence of ongoing development capacity.
The repository has only 2 stars and no forks, indicating a small user and contributor community. Low popularity is supporting evidence rather than a health verdict, but it limits visible resilience.
The repository uses Composer and Robo for builds, which is positive, but it reports no security scanning tools. That leaves a gap in automated security hygiene.
The repository has no published security policy. This does not show a defect in the package, but it reduces transparency about how vulnerabilities are reported and handled.
The single workflow was fully analyzed with no reported audit findings or untrusted checkout paths. However, both analyzed action references are unpinned, so their future contents could change unexpectedly.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.2|^4.7 | — | — |
symfony/config Version ~5.0|~6.0|~7.0|~8.0 | — | — |
symfony/console Version ~4.0|~5.0|~6.0|~7.0 | — | — |
symfony/expression-language Version ~6.0 | — | — |
symfony/dependency-injection Version ~5.0|~6.0|~7.0|~8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.