This is a reasonably healthy, clearly maintained organization-backed Symfony/Sulu bundle with a matching repository, MIT licensing, comprehensive tests, documented usage, stable releases, and no deprecation or archived-repository indicators. The main concern is that the repository recorded no commits and no active maintainers in the last 3 months, while security scanning and a repository security policy are absent and the workflow does not declare top-level token permissions; however, these are hygiene and recent-activity concerns rather than evidence that the package is unfit to depend on.
78%
Total Score
88
100
89
80
There were 0 commits and 0 active maintainers in the last 3 months, which is a caution for recent maintenance momentum; the recent release and push provide partial evidence of continued activity but do not remove the slowdown concern.
The repository has 6 stars, 0 forks, and 1 watcher, indicating limited adoption. Popularity is supporting evidence only, so this lowers confidence in ecosystem validation but is not itself a dependency-health failure.
Composer build tooling is present, but no security scanning tools are configured. The missing scanning is a genuine security-process hygiene gap, though it is not evidence of maliciousness or abandonment.
No repository security policy was found, which reduces transparency around vulnerability reporting and response expectations.
The only workflow lacks top-level token permissions. No write permissions were observed, but explicitly constraining permissions would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sulu/sulu Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.