This is a generally usable and actively published package with a stable v1.0.1 release, 12 releases since February 2023, a non-deprecated registry status, an unarchived repository, an MIT license, and an organization-backed project. The main concerns are limited recent maintenance capacity—only 1 commit from 1 active maintainer over the last 3 months, with all recent commits concentrated in one contributor—plus the absence of repository tests, a changelog, security scanning, and a security policy. The very low repository popularity is supporting caution but is not decisive by itself; review compatibility and maintenance expectations before adopting it as a core dependency.
72%
Total Score
75
100
83
83
The package has a substantial 7,364-character README, but neither the artifact nor repository has tests or a changelog. These omissions reduce maintenance and release transparency for a framework plugin.
All recent commits came from one contributor, giving a top-contributor share of 100%. The organization-owned repository provides some handoff potential, but no second recently active contributor is shown.
Only 1 commit was recorded in the last 3 months from 1 active maintainer. Recent publishing activity partly compensates, but the low direct commit volume leaves maintenance capacity uncertain.
The repository has only 1 star, 2 forks, and 4 watchers. This limits community validation and support signals, but popularity is supporting evidence rather than a health verdict.
Composer is used as the build tool, which is appropriate for a Packagist PHP package, but no security scanning tools are configured. The missing scanning is a hygiene gap rather than evidence of maliciousness.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
symfony/form Version ^7.4 | — | — |
sylius/sylius Version ^2.0 | — | — |
symfony/twig-bundle Version ^7.4 | — | — |
symfony/framework-bundle Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.