The package is licensed, documented, and its repository matches the package; its single workflow completed cleanly. Maintenance and security coverage remain limited, so pin this version and test it against your Pimcore release.
58%
Total Score
75
100
88
50
The package has 32 releases, but none in the last 12 months and the latest registry release was about 4 years and 6 months ago. This is the main maintenance concern, despite a historically regular release cadence.
There were no commits and no active maintainers in the last 3 months. Combined with the old registry release, this indicates limited current maintenance capacity.
Composer build tooling is present, but no security scanning tools were detected. That is a transparency and maintenance gap, though it is not evidence of malicious behavior.
The repository has no security policy, leaving no documented path for reporting or handling vulnerabilities. This lowers transparency for a package that runs inside a Pimcore application.
The only workflow was fully analyzed with no reported audit findings or untrusted checkout or script-injection paths. Its one action use is unpinned, which is a minor reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pimcore/pimcore Version >=6.3 | — | — |
dpfaffenbauer/process-manager Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.