The release includes tests, detailed documentation, and notes for this exact fix. Composer security auditing and a non-archived repository add useful safeguards, though ongoing review depends heavily on one contributor.
78%
Total Score
67
100
67
The repository is owned by an individual user rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.
Only one contributor made all 45 commits in the last 3 months, leaving no demonstrated backup for maintenance. The active commit volume helps, but does not remove this succession risk.
The repository has no security policy. For a tracking bundle handling application data, that is a transparency gap, although the repository does use Composer security scanning.
Both workflows were analyzed without failures and no dangerous sinks or audit findings were reported. However, all 7 action references are unpinned and one release workflow grants top-level write access, creating moderate workflow hygiene and reproducibility concerns without an observed exploit path.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^2|^3 | — | — |
doctrine/orm Version ^3.3|^4.0 | — | — |
symfony/yaml Version ^7.3|^8.0 | — | — |
doctrine/dbal Version ^3|^4 | — | — |
symfony/string Version ^7.3|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.