The repository is active and the organization provides some handoff capacity, with a current release, README, changelog, and security tooling. Maintenance is thin and workflow dependencies are all unpinned; the missing security policy adds a smaller transparency gap.
68%
Total Score
67
94
75
The package is 650 days old with three releases, only one release in the last 12 months, and a median interval of about 316 days. The latest release was published recently, so this indicates slow rather than absent maintenance.
All recent commits came from one contributor, giving the project a single-person operational dependency. Organization ownership provides some potential handoff capacity, but no second active contributor is shown.
There was one commit in the last three months from one active maintainer. Recent activity is positive, but the very low volume provides limited evidence of sustained maintenance.
No repository security policy was found. This is a transparency gap, though security scanning tools provide some compensating process evidence.
The sole workflow was fully analyzed with no untrusted checkouts, injection findings, or excessive top-level permissions. However, all four referenced actions are unpinned, leaving builds exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sulu/sulu Version ^2.6 | — | — |
pixelmairie/sulu-townhallbundle Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.