Usable with caveats: it has a stable release, frequent publishing, clear documentation, tests, and an active source repository. Adoption carries some maintenance risk because recent work is concentrated in one contributor and the repository lacks a security policy and explicit workflow permissions.
74%
Total Score
67
100
89
75
All recent repository activity comes from one contributor, creating a meaningful continuity risk if that maintainer becomes unavailable. The repository is user-owned rather than organization-backed, so there is no shown organizational handoff capacity to offset this concentration.
Only one commit was recorded in the last three months, which is limited activity for a recently released package and leaves some uncertainty about ongoing maintenance.
The repository has three stars, no forks, and one watcher. This is limited adoption evidence, but popularity is only supporting evidence and does not outweigh the package's release, documentation, and repository signals.
Composer is used as a build tool, but no security scanning tools were detected. The absence of scanning reduces supply-chain transparency somewhat, though it is not by itself evidence of unsafe code.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sulu/sulu Version ^3.0 | — | — |
symfony/config Version ^5.4 || ^6.0 || ^7.0 | — | — |
symfony/http-kernel Version ^5.4 || ^6.0 || ^7.0 | — | — |
symfony/dependency-injection Version ^5.4 || ^6.0 || ^7.0 | — | — |
symfony/translation-contracts Version ^2.5 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.