Documentation, tests, and release notes make the package easy to evaluate. The organization-backed repository is current, but recent work is concentrated in one contributor and all 13 actions are unpinned.
78%
Total Score
67
100
50
One contributor made all recent commits, concentrating current maintenance knowledge. Organization ownership provides some handoff capacity but does not remove the near-term concentration risk.
Only one commit was recorded in the last three months, so current development activity is limited even though the repository has a recent release.
The repository has no SECURITY.md or other detected security policy, leaving vulnerability reporting and response expectations less transparent.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 13 analyzed action references are unpinned, which is a workflow supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^7.4|^8.0 | — | — |
symfony/console Version ^7.4|^8.0 | — | — |
symfony/http-kernel Version ^7.4|^8.0 | — | — |
symfony/event-dispatcher Version ^7.4|^8.0 | — | — |
symfony/dependency-injection Version ^7.4|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.