An organization-backed repository includes a README, tests, a matching package name, and a clear MIT license. No security policy or automated security scanning is present, so ongoing oversight is limited.
63%
Total Score
75
100
89
50
The repository recorded zero commits and zero active maintainers in the past three months, which is a meaningful maintenance and abandonment concern for a young package.
The repository has zero stars, forks, and watchers. This provides little external validation, but popularity is only supporting evidence and the project has organization backing.
The repository uses Make and Composer, but no security scanning tools were detected. This leaves supply-chain and code-quality oversight weaker than it could be.
No repository security policy was found, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sylius/sylius Version ^2.0 | — | — |
sylius/invoicing-plugin Version ^0.20 || ^2.0 | — | — |
symfony/framework-bundle Version ^6.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.