The package is correctly linked to its source and has clear MIT licensing. Its tiny README, absent security policy, and minimal project activity leave substantial maintenance risk.
42%
Total Score
50
63
75
Only two releases were published, with none in the last seven years and none in the past 12 months. This strongly suggests the package is no longer actively maintained.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
A GitHub release note documents this version, but the package README contains only eight characters and the repository has no tests or changelog. The release note partly compensates for missing changelog material, not the inadequate consumer documentation.
The repository has one star and no forks, providing little evidence of a broad user or contributor base. Popularity is supporting evidence, but this reinforces the maintenance concerns.
Composer build tooling is present, which supports a recognizable build process, but no security-scanning tooling is configured and the project has no recent activity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^3.7 | — | — |
twig/extensions Version ^1.5 | — | — |
fzaninotto/faker Version ^1.7 | — | — |
sylius/grid-bundle Version ^1.2 | — | — |
sylius/user-bundle Version ^1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.