An empty vivutio installation: the core and nothing else, the same for every supplier, operator and agent. Add the modules that apply to you.
58%
Total Score
caution
A two-day-old package has one active contributor and a high-confidence release-workflow issue with every action unpinned.
The audit covered both workflows and found a high-confidence template-injection issue in release.yml; all six action references are unpinned, and one workflow grants top-level write access. No untrusted checkout or script-injection trigger was found to compound the issue.
Composer runs post-install and post-update scripts, which is common for Symfony packages but adds install-time behavior that consumers should understand.
Six releases in two days show active development, but a package age of only two days provides almost no evidence of long-term maintenance or release discipline.
One contributor made all six recent commits, creating a low bus factor. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Six commits in the last three months, all concentrated in one active maintainer, show recent work but limited evidence of sustained maintenance capacity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/flex Version ^2.11 | — | — |
symfony/yaml Version 8.1.* | — | — |
symfony/dotenv Version 8.1.* | — | — |
symfony/console Version 8.1.* | — | — |
symfony/runtime Version 8.1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.