Documentation and project structure are solid, with automated security scanning and organization backing. Its single release in about two years and four months, plus zero recent commits, make future fixes uncertain; pin 2.5.0 if adopting.
55%
Total Score
67
93
50
This is the package's only release, published about two years and four months ago, with no releases in the last 12 months. That limited history and lack of ongoing delivery reduce confidence in future maintenance.
The repository recorded zero commits and zero active maintainers in the last three months. The repository is not archived, but this still leaves maintenance responsiveness uncertain.
There were no new or closed issues or pull requests in the last month, while one issue and two pull requests remain open. This is a modest sign of limited current project activity.
The repository has no published security policy, leaving the process for reporting and handling vulnerabilities unclear. Security scanning tools provide some compensation but do not replace a response policy.
The workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all four action references are unpinned. Unpinned actions weaken build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sulu/sulu Version ^2.4 | — | — |
symfony/config Version ^5.0 || ^6.0 | — | — |
symfony/http-kernel Version ^5.0 || ^6.0 | — | — |
symfony/http-foundation Version ^5.0 || ^6.0 | — | — |
symfony/framework-bundle Version ^5.0 || ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.