Tests, release notes, and security scanning provide useful support. The package remains early-stage, with a small audience and limited evidence of sustained maintenance.
62%
Total Score
50
80
50
The package has six releases, but none in the last 12 months despite being about 435 days old. This weakens evidence of ongoing maintenance, although the recent repository push provides some counterweight.
The repository records zero commits and zero active maintainers during the last 3 months. That is a meaningful maintenance concern, though the repository is not archived and was pushed recently.
The repository has no published security policy, reducing transparency about how vulnerability reports should be handled. This is a minor concern rather than evidence of abandonment by itself.
Version v0.1.2 is not a stable major release, so compatibility and maturity remain less established. It is not marked as a prerelease, which modestly offsets the concern.
The single workflow was fully analyzed with no dangerous triggers, sinks, or audit findings. However, both action references are unpinned, leaving the workflow exposed to changes in referenced actions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
webmozart/assert Version ^1.11 | — | — |
symfony/http-kernel Version ^6.0|^7.0 | — | — |
symfony/remote-event Version ^6.0|^7.0 | — | — |
symfony/http-foundation Version ^6.0|^7.0 | — | — |
symfony/framework-bundle Version ^5.4|^6.0|^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.