The README, test suite, license, and organization ownership provide useful supporting evidence. The project is still very new, and its workflow references are not pinned, so reassess after a longer maintenance track record.
65%
Total Score
75
83
50
The package is only 2 days old, despite 16 releases in that period; this shows activity but leaves little evidence of long-term maintenance or release stability.
All 89 commits in the last 3 months came from one contributor, creating a meaningful continuity risk; organization ownership provides some capacity for handoff but does not show another active contributor.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in a security-sensitive application foundation.
Version v0.10.15 is not a stable major release, although it is not marked as a prerelease and recent releases have not been prereleases.
The single workflow was fully analyzed, uses read-only permissions, and has no untrusted checkout or injection findings, but all 3 action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/flex Version ^2.11 | — | — |
symfony/yaml Version 8.1.* | — | — |
symfony/dotenv Version 8.1.* | — | — |
symfony/console Version 8.1.* | — | — |
symfony/runtime Version 8.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.