The MIT declaration, substantial README, and read-only workflow permissions improve transparency and reduce operational risk. Both workflow actions are unpinned, and the repository has no security policy, leaving avoidable maintenance and supply-chain gaps.
61%
Total Score
50
86
75
No commits or active maintainers were recorded in the last three months, which is a meaningful maintenance concern for a package with a recent release history.
Composer build tooling is present, but no security scanning tools were detected, leaving security maintenance less visible.
The repository has no security policy, reducing transparency about how consumers should report and handle security issues.
The v0.5.0 release is not a stable major version, so compatibility expectations remain lower even though it is not marked as a prerelease.
The workflow scopes permissions read-only and has no audit findings, but both of its two action references are unpinned, weakening build reproducibility and action supply-chain protection.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sulu/sulu Version ^2.6 || ^3.0 | — | — |
symfony/intl Version ^6.2 | ^7.0 | — | — |
sulu/sulu-rector Version ^2.0 | — | — |
symfony/translation Version ^6.2 | ^7.0 | — | — |
doctrine/doctrine-bundle Version ^2.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.