This is internal package, will broke your code
42%
Total Score
50
64
50
There have been no releases in the past 12 months, despite 39 releases overall; this indicates the package may no longer be actively maintained.
The repository had zero commits and zero active maintainers in the last 3 months, reinforcing the concern that maintenance has stalled.
The package declares a proprietary license, but no license file was detected in the artifact or repository, limiting transparency for an open-source dependency.
Composer install and update lifecycle scripts run during package operations, creating additional execution surface for consumers even though such scripts can be normal for PHP packages.
The repository name does not match the package and its README does not mention the package, so the package-to-source relationship is not clearly established.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sylius/sylius Version ^v1.13 | — | — |
sylius/mailer-bundle Version ^1.8 || ^2.0@beta | — | — |
loevgaard/sylius-brand-plugin Version ^2.2 | — | — |
symfony/webpack-encore-bundle Version ^1.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.