The package includes tests, a substantial README, and a declared license, which support basic maintainability and adoption. Its only release was over five years ago, repository activity stopped shortly afterward, and the project has no security policy or scanning tools.
38%
Total Score
57
67
Only one release exists, published over five years ago, with no releases in the last 12 months. This is strong evidence of an unmaintained release line.
The repository is not archived, but it was last pushed over five years ago. The non-archived status does not compensate for the prolonged absence of source activity.
The package declares post-create-project-cmd, post-install-cmd, and post-update-cmd scripts. Install-time scripts add operational exposure and warrant review, but their presence alone is not evidence of poor maintenance.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than decisive, but these figures provide no sign of an active user or contributor community.
Composer is used for builds, but no security scanning tools are present. The missing scanning reduces supply-chain maintenance evidence without proving the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sylius/sylius Version ^1.7.5 | — | — |
theofidry/alice-data-fixtures Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.