The package is well documented and licensed, with a recent release, release notes, and a focused dependency set. Maintenance is concentrated in one contributor, while workflow references are entirely unpinned and the repository has no security policy.
70%
Total Score
75
100
100
50
One contributor made all 20 commits in the last 3 months, creating a meaningful continuity risk despite the project's active release and commit history.
The repository has no SECURITY.md or other security policy, leaving vulnerability reporting and response expectations undocumented.
All 14 analyzed action references are unpinned, which weakens build reproducibility, and the audit found two high-confidence template-injection findings. There are no untrusted checkouts or script-injection counts, so these workflow issues are hygiene concerns rather than standalone severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
symfony/console Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.