Clear licensing, documentation, tests, and release notes support straightforward integration. The workflow has no dangerous findings, but all nine actions are unpinned and no security policy is provided.
79%
Total Score
75
100
94
83
The repository recorded zero commits and zero active maintainers in the last three months. This is a maintenance caution, partly offset by the recent release and February push.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence the release is unsafe.
No repository security policy was found. That weakens vulnerability-reporting transparency, though it does not by itself indicate abandonment.
The single workflow was fully analyzed with no dangerous audit findings or untrusted checkouts, and it has no top-level write permissions. However, all 9 action references are unpinned, leaving avoidable workflow supply-chain drift.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^6.4 || ^7.0 || ^8.0 | — | — |
php-http/discovery Version ^1.20 | — | — |
geocoder-php/plugin Version ^1.6 | — | — |
willdurand/geocoder Version ^4.6|^5.0 | — | — |
symfony/framework-bundle Version ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.