The package has clear documentation, a matching organization-backed repository, and a changelog. Its lack of recent security tooling and the proprietary license add adoption friction for teams needing long-term transparency.
43%
Total Score
50
69
75
The package has had no releases in nearly five years, despite nine releases since May 2020; this is strong evidence that maintenance has stopped.
There were zero commits and zero active maintainers in the last three months, consistent with the release history and indicating a severe abandonment concern.
The manifest declares a proprietary license, so the release is licensed; however, the absence of a license file leaves the exact terms less transparent to consumers.
Composer is used for builds, but no security scanning tools are present, leaving a maintenance and vulnerability-detection gap.
The linked repository is not archived, but its last push was in October 2021, so the non-archived status provides limited reassurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
akeneo/pim-community-dev Version ~4.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.