It has a clear MIT license, matching source repository, regular releases, and release notes for this version. The lack of recent commits, security scanning, and a security policy leaves maintenance and response capacity less reassuring.
68%
Total Score
75
100
89
67
Composer install, update, and project-creation lifecycle scripts add execution during dependency operations; their presence is a supply-chain hygiene concern even though no harmful behavior is established here.
The repository recorded zero commits and zero active maintainers in the last three months, which weakens confidence in current maintenance despite the recent push and release history.
The repository has only 2 stars and 6 forks, indicating limited adoption, but popularity is supporting evidence rather than a health verdict.
The repository uses Composer and Make, but no security-scanning tools were detected, leaving automated security coverage unclear.
The repository has no security policy, so users have no documented route or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sylius/sylius Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.