Clear documentation, repository tests, and release notes make the package easy to assess. Maintenance has been quiet since the April 2025 release, while workflow pinning and review hygiene need attention.
68%
Total Score
75
92
50
The package has 28 releases over about six years, but the latest release was April 20, 2025, with no releases in the following 12 months of the collected history. That is a meaningful maintenance concern for a library dependency.
The repository recorded no commits and no active maintainers in the last three months. Although it was pushed in December 2025, the recent activity measure indicates a currently quiet project.
The repository has no security policy. This is a transparency gap, though the project does use Dependabot and the absence does not by itself indicate abandonment.
All 19 analyzed action references are unpinned, and the audit found a high-confidence unsound condition in auto-review.yaml. No untrusted checkout or script-injection path was found, which limits the impact but does not remove the workflow hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1.4 || ^2.0 || ^3.0.2 | — | — |
nikic/iter Version ^2.4.1 | — | — |
symfony/console Version ^6.4.17 || ^7.2.1 | — | — |
symfony/process Version ^6.4.19 || ^7.2.4 | — | — |
webmozart/assert Version ^1.11 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.