58%
Total Score
caution
Usable with caveats: no commits in three months, a proprietary license, and weak package-to-repository identification reduce confidence.
The release declares a proprietary license but provides no recognized license text or license file, limiting transparency and reuse confidence.
Composer install, update, and create-project hooks expand installation behavior and deserve care, although their presence alone does not show harmful or unnecessary actions.
The repository recorded zero commits and zero active maintainers in the last three months, which weakens evidence of ongoing maintenance despite a recent package release.
The repository name does not match the package name and its README does not mention the package, making the package-to-source relationship less transparent; organizational backing partly offsets this concern.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sylius/sylius Version ^1.12.13 | — | — |
webimpress/safe-writer Version ^2.2 | — | — |
setono/doctrine-orm-trait Version ^1.1 | — | — |
symfony/webpack-encore-bundle Version ^1.15 | — | — |
setono/doctrine-object-manager-trait Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.