The package is clearly documented, licensed, and tied to an organization-owned project with a matching repository reference. Its lack of security-policy and scanning evidence adds maintenance risk for a dependency that has otherwise seen little recent activity.
38%
Total Score
63
100
75
75
The last registry release was over 7 years ago, despite 25 releases historically and a previously regular median interval of about 24 days. No releases appeared in the last 12 months, which is a substantial abandonment concern.
There were zero commits and zero active maintainers in the last 3 months. Combined with the last release being over 7 years ago, this is strong evidence that ongoing maintenance capacity is limited.
There were no new or closed issues or pull requests in the last month, with 5 issues and 1 pull request still open. This supports the conclusion that the project is not actively maintained.
Composer build tooling is present, but no security-scanning tools were detected. The missing security automation is a hygiene gap that matters more for an old dependency with little recent activity.
The linked repository is not archived, so the project remains technically open for maintenance. Its last push was about 5 years ago, which limits the reassurance this provides.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
akeneo/pim-community-dev Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.