The source has recent commits from five contributors, tests, release notes, and a security policy. All 20 workflow actions are unpinned, and the audit found two high-confidence template-injection issues.
62%
Total Score
100
81
100
Packagist marks the package abandoned at package scope, although the stated replacement is the same package and the linked repository remains active. This is a meaningful registry-maintenance warning but not evidence that the source project is abandoned.
The project has 93 releases since September 2015, but only one release in the last 12 months. Recent repository activity partly offsets the slower registry cadence.
All 20 analyzed action references are unpinned, which weakens build reproducibility. The audit also found two high-confidence template-injection findings; no untrusted checkout or script-injection trigger was reported, so these remain workflow-hygiene concerns rather than a standalone severe verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/polyfill-mbstring Version ^1.24 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.