Usable with caveats: the repository is active, well-scaffolded, and backed by an organization, but this is a new 0.1.0 package with only one registry release and highly concentrated recent contributions. The repository also lacks a security policy and explicit workflow token permissions.
72%
Total Score
83
100
86
80
Only one release has been published, and the package is 79 days old, so there is little evidence yet of long-term release continuity or compatibility maintenance.
One contributor made 36 of 38 recent commits, creating substantial concentration risk; the second active contributor and organization ownership provide partial compensation, so this remains a caution rather than a severe abandonment signal.
No repository security policy was found, leaving vulnerability-reporting and response expectations less transparent for users of this plugin.
The only workflow does not declare top-level token permissions. Although no write permissions were observed, explicit least-privilege settings would provide stronger workflow security hygiene.
Version 0.1.0 is not a stable major release, indicating an early API and maturity stage even though it is not marked as a prerelease.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sylius/sylius Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.