The library is small and focused, with a lightweight runtime dependency set and no install-time scripts. Its quiet recent commit window and unpinned workflow actions are modest reservations.
78%
Total Score
75
100
100
75
There were no commits and no active maintainers in the three months before collection. Because a release was published during that broader period, this is a maintenance concern but not evidence of abandonment on its own.
The repository has no published security policy. This is a transparency gap for reporting vulnerabilities, although the project has other quality tooling.
All three workflows were analyzed successfully with no untrusted checkouts, script injection, or high-severity findings. However, all seven action references are unpinned, leaving workflow builds exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^3.4.31|^4.3.4|^5.0|^6.0|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.