This is a usable but relatively young Sylius plugin with a clear MIT license, documentation, tests, a substantial source tree, recent releases, an active non-archived repository, and useful build and security tooling. However, maintenance capacity is thin: only one commit from one active maintainer occurred in the last 3 months, all recent commit activity is concentrated in that contributor, and 12 pull requests are open with only one merged in the last month. The pre-1.0 version also indicates limited maturity, while the repository lacks a security policy and does not declare top-level workflow permissions. I would consider depending on it with review and an adoption plan, but not treat it as a low-maintenance, highly mature dependency.
68%
Total Score
63
100
89
70
Composer install, update, and project-creation lifecycle scripts are present. These add execution surface during dependency operations, but no evidence here shows that they are unsafe or unusually risky.
All recent commits come from one contributor with a 100% share, creating a meaningful continuity and abandonment risk. Organization ownership offers some potential handoff capacity, but no second active contributor is shown.
Only 1 commit was recorded in the last 3 months from 1 active maintainer. The recent release and current repository push provide some compensating evidence, but the observed development pace is thin.
There are no open issues and one pull request was merged in the last month, but 12 pull requests remain open and there were no new or closed issues in that period, suggesting limited visible throughput.
The repository has only 1 star, 0 forks, and 4 watchers. This is weak supporting evidence for community adoption, although popularity alone is not decisive for a specialized plugin.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sylius/sylius Version ^1.12 | — | — |
symfony/webpack-encore-bundle Version ^1.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.