Tests, release notes, and a clear MIT license improve confidence. The repository has no commits in the last three months, while every workflow action is unpinned and one uses an archived action. Pin v1.1.0 and verify ongoing maintenance before broad adoption.
65%
Total Score
50
100
94
50
The package runs post-install and post-update Composer scripts. These are common for PHP packages, but they add installation-time behavior that consumers should understand.
There were no commits and no active maintainers in the last three months. This is a meaningful maintenance concern, although the release history shows the package was published recently.
The repository name does not match the package name and its README does not mention the package, so the package-to-source relationship is less transparent even though the repository owner matches the registry organization.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
All 15 analyzed action references are unpinned, and a high-confidence audit finding identifies an archived action; these weaken workflow supply-chain hygiene. The cache-poisoning findings are low confidence and do not materially change the assessment.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/lock Version ^6.4 || ^7.1 | — | — |
sylius/sylius Version ^2.0 | — | — |
webmozart/assert Version ^1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.