It includes a clear MIT license, tests, release notes, and a repository that matches the package. These positives improve transparency but do not provide current support for new adopters.
12%
Total Score
50
50
Packagist marks the entire package as abandoned and names sulu/skeleton as its replacement. Package-level deprecation is a severe adoption risk, not merely a warning about this release.
The package has 91 releases since August 2016, but none in the last 12 months and its latest release was in June 2022. The long gap is consistent with abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months. This provides no evidence of current maintenance capacity.
The linked sulu/sulu-minimal repository is archived, which indicates the source project is no longer intended for ongoing maintenance. Its recorded push in December 2025 does not offset the archived status.
The single workflow was fully analyzed with no untrusted checkout, injection, or audit findings, but all 3 action references are unpinned. That is a mild reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sulu/sulu Version 2.0.0-RC2 | — | — |
symfony/config Version ^3.4 || ^4.0 | — | — |
symfony/dotenv Version ^3.4 || ^4.0 | — | — |
twig/extensions Version ^1.0 | — | — |
symfony/twig-bundle Version ^3.4 || ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.