Documentation, tests, and release notes make integration easier. CI is configured, though its reusable workflow passes secrets broadly. Longer-term maintenance remains unproven for this newly published package.
68%
Total Score
83
93
50
The package was first released today and has only one release, so there is no demonstrated long-term maintenance record yet.
All seven commits in the last three months came from one contributor. Organization backing helps provide continuity, but no second active contributor is shown.
No repository security policy was found. This is a transparency gap, but it is not severe enough by itself to make the release unfit.
The single workflow has no untrusted checkout or script-injection findings and pins its analyzed action, but it uses top-level write permissions and a high-confidence secrets-inherit finding, creating a meaningful CI hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^3.0 | — | — |
symfony/config Version ^8.1.5 | — | — |
symfony/console Version ^8.1.7 | — | — |
symfony/http-kernel Version ^8.1.7 | — | — |
symfony/dependency-injection Version ^8.1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.