It includes tests, a README, release notes, and a matching license. The repository has no security policy and its install hooks and workflow setup add maintenance overhead.
57%
Total Score
75
93
50
The package runs post-install and post-update scripts, which increases installation complexity and the code executed during dependency operations. No other provided signal shows these hooks are unsafe, so this is a limited concern rather than a severe risk.
This is the only release, published about two years ago, with no releases in the last 12 months. That leaves maintenance and compatibility uncertain for a package intended as a reusable tool.
The repository recorded no commits and no active maintainers in the last three months, consistent with the package having remained unchanged since its first release. This is meaningful abandonment risk despite the repository not being archived.
The repository has no security policy. For a validation tool this is a transparency and vulnerability-reporting gap, although tests, a public repository, and release notes provide some compensating evidence.
Both workflows were fully analyzed with no untrusted checkouts, script injection, or audit findings, but all 8 action references are unpinned. The clean audit offsets some concern, while unpinned references remain a workflow reproducibility and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/flex Version ^2 | — | — |
symfony/yaml Version 7.1.* | — | — |
symfony/dotenv Version 7.1.* | — | — |
symfony/console Version 7.1.* | — | — |
symfony/runtime Version 7.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.