The MIT license, release notes, repository tests, and recent merged work make the package transparent to evaluate. Its broad Symfony dependency set and absent security policy leave less margin for long-term maintenance.
66%
Total Score
75
50
86
50
The plugin declares 28 runtime dependencies across Sylius, Symfony, Doctrine, and related components; that is expected for this integration but increases upgrade and compatibility exposure.
One contributor made all 28 recent commits, which creates a clear continuity risk; organization ownership provides some backing but no second active contributor is shown.
The repository recorded 28 commits in the last 3 months, but all were made by one active maintainer, leaving maintenance capacity concentrated.
Composer build tooling is present, but no security scanning tools were detected, reducing evidence of systematic dependency or code-security checks.
The repository has no security policy, so users are given no documented security-reporting or response process.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
twig/twig Version ^2.15 || ^3.22 | — | — |
sylius/core Version ^1.0 | — | — |
doctrine/orm Version ^2.0 | — | — |
sylius/order Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.