Healthy and usable for a Sulu project. It has a current stable release, a matching active repository, release notes, and clear documentation, but maintenance is lightly staffed with only one recent contributor and limited release history.
78%
Total Score
67
100
94
80
All recent commits came from one contributor, creating concentration risk. The repository is owned by an organization, which provides some ability to hand maintenance to another person, but no second active contributor is shown.
There was 1 commit from 1 active maintainer in the last 3 months. Recent activity is present but sparse, so maintenance capacity is thinner than the current release date alone suggests.
The repository has 1 star, 0 forks, and 1 watcher. This is weak supporting evidence of community adoption, but popularity is not decisive because the repository otherwise matches the package and is maintained.
No repository security policy was found. This is a transparency gap for reporting vulnerabilities, though the repository does have automated security scanning.
The only workflow lacks a top-level token-permissions declaration, so its GitHub Actions permissions are not explicitly restricted. No top-level write permission was observed, making this a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sulu/sulu Version ^2.6 | — | — |
symfony/config Version ^5.0 || ^6.0 | — | — |
symfony/http-kernel Version ^5.0 || ^6.0 | — | — |
symfony/http-foundation Version ^5.0 || ^6.0 | — | — |
symfony/framework-bundle Version ^5.0 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.