The GPL-2.0-only license, included tests, and absence of install scripts make its intended use clear. CI was fully audited, but all 10 action references are unpinned, adding reproducibility risk.
10%
Total Score
0
40
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on the release.
Only one release exists, published nearly 3 years ago, with no releases in the last 12 months. The single-release history reinforces the abandonment concern.
There were no commits and no active maintainers in the last 3 months. Together with the archived repository, this indicates no current maintenance capacity.
The linked repository is archived and was last pushed nearly 3 years ago, so new fixes and maintenance should not be expected.
The repository has no security policy. This is a transparency gap, although the package's archived and abandoned status already dominates the assessment.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ibexa/core Version ^4.5 | — | — |
symfony/yaml Version ^5.4 | — | — |
symfony/config Version ^5.4 | — | — |
symfony/http-kernel Version ^5.4 | — | — |
ibexa/product-catalog Version ^4.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.