Plug-and-play Sylius wrapper for the Honkers chatbot tool-server: default tools, data sources and shop widget
68%
Total Score
caution
A new package with one maintainer and unpinned workflow actions has a limited track record.
The repository is owned by a personal GitHub account rather than an organization, so the single-contributor concentration is not visibly offset by organizational backing.
The package was first released 0 days ago and has 13 releases in that period, so it shows active initial work but no long-term maintenance history.
All 40 recent commits came from one contributor, leaving no demonstrated handoff capacity if that person becomes unavailable.
Composer is used for builds, but no security scanning tool was detected. This is a transparency and maintenance gap rather than evidence of a direct defect.
The repository has no security policy, so vulnerability reporting and response expectations are not documented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.12 || ^3.3 | — | — |
doctrine/orm Version ^2.20 || ^3.6 || ^4.0 | — | — |
symfony/intl Version ^6.4 || ^7.0 || ^8.0 | — | — |
sylius/sylius Version ^1.14 || ^2.2 || ^2.3@alpha | — | — |
symfony/config Version ^6.4 || ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.