The repository includes tests, a changelog, and a clear README, but this is a brand-new v0.1.0 package with no maintenance history yet. Its workflow uses two unpinned actions and the project has no security scanning or policy, so keep the dependency pinned while it matures.
68%
Total Score
100
100
81
75
This is the only release and was published 0 days ago, so there is no observed release cadence or track record to demonstrate sustained maintenance.
Composer build tooling is present, but no security scanning tools were detected. That leaves a modest transparency and maintenance gap, partially offset by the clean workflow audit.
No repository security policy was found. This is a minor transparency gap for a package handling authentication and SOAP integration, but it is not evidence of unsafe behavior on its own.
v0.1.0 is an early major version, which indicates an immature compatibility and stability track record even though it is not marked as a prerelease.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both of its two action references are unpinned, which weakens build reproducibility; the missing top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
symfony/config Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/routing Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/http-kernel Version ^6.4 || ^7.0 || ^8.0 | — | — |
symfony/security-core Version ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.