Documentation, tests, release notes, and MIT licensing give adopters a solid baseline. The organization-backed project remains credible, but workflow hygiene is weak and recent maintenance is limited.
58%
Total Score
67
88
50
The package has 84 releases since August 2017, but no releases in the last 12 months; the latest release was about 18 months ago. This materially raises maintenance risk despite the historically regular release cadence.
The repository recorded zero commits and zero active maintainers in the last 3 months. Combined with no registry releases in the last year, this is a meaningful sign of slowed maintenance.
There were no new or closed issues or pull requests in the last month, with only three open issues and two open pull requests. This is a modest corroborating sign of low current activity rather than evidence of abandonment on its own.
The project uses Composer build tooling, but no security scanning tools were detected. The missing scanning is a transparency and hygiene gap, not a severe dependency risk by itself.
The repository has no documented security policy. For a maintained application plugin, this reduces transparency about vulnerability reporting and handling.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^9.1 | — | — |
sylius/sylius Version ^1.13 | — | — |
instaclick/php-webdriver Version ^1.4 | — | — |
symfony/webpack-encore-bundle Version ^1.12 | — | — |
friendsofsymfony/ckeditor-bundle Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.