It includes a README, release notes, repository tests, and a matching MIT license. The repository is not archived and has clear organizational backing, but ongoing maintenance is currently absent.
58%
Total Score
50
90
The package has 29 releases since September 2021, but none in the last 12 months; the latest release was about 17 months ago. This indicates a meaningful maintenance slowdown despite a previously active release cadence.
The repository recorded no commits and no active maintainers in the last three months. That is direct evidence of currently absent development activity and raises abandonment risk.
All 13 analyzed action references are unpinned, and the audit reported a low-confidence cache-poisoning pattern. The workflow was fully analyzed and has no untrusted checkout or script-injection findings, so this is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache Version ^5.4.46 | — | — |
composer/semver Version ^3.4.3 | — | — |
symfony/console Version ^5.4.47 | — | — |
symfony/filesystem Version ^5.4.45 | — | — |
symfony/http-client Version ^5.4.49 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.