The package has clear installation documentation, tests, regular releases, and an organization owner. Its small public footprint makes long-term support less certain.
70%
Total Score
67
100
94
50
Composer install, update, and project-creation lifecycle scripts are present. They add execution during dependency operations and warrant attention, but this signal alone does not show unsafe behavior.
One contributor made 100% of the commits in the last three months. Organization ownership provides some handoff capacity, but no second recently active contributor is shown.
Only one commit was recorded in the last three months, from one active maintainer. Recent release activity offsets this somewhat, but the repository's ongoing maintenance activity is thin.
The repository has five stars and no forks or watchers. This is limited adoption evidence, but popularity is supporting context rather than a health verdict.
No security policy is present in the repository. For an authentication plugin, this is a meaningful transparency gap because it gives users no stated process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sylius/sylius Version ~2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.