This release appears healthy and suitable for dependency use: it is a stable, non-prerelease version with regular releases, was published recently, is not deprecated, and is backed by an active, non-archived organization-owned repository. The repository contains comprehensive tests, a license, build configuration, and safe workflow analysis, while recent commits involve two contributors and the package has a small, focused runtime dependency profile. The main reservations are modest repository popularity, no dedicated security policy, and a workflow without explicitly declared top-level token permissions; these are transparency and hardening gaps rather than evidence of abandonment or unfitness.
86%
Total Score
100
100
89
80
The repository has 9 stars, 1 fork, and 2 watchers. This is limited adoption evidence, but popularity is only supporting evidence and does not outweigh the active maintenance signals.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning automation is a hardening gap, though other repository and workflow signals are healthy.
The repository has no SECURITY.md or other detected security policy, which reduces vulnerability-reporting transparency for dependents.
The only workflow lacks top-level token permissions declarations. No write permissions were detected, but explicit least-privilege configuration would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sulu/sulu Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.