The 0.x version and fully unpinned workflow actions add avoidable adoption and build-integrity concerns. Organization backing, tests, release notes, and a security policy provide useful support for continued maintenance.
63%
Total Score
67
50
81
100
Thirteen runtime dependencies, including several Symfony and Sylius components, create meaningful compatibility surface area for a 0.x bundle. The profile is coherent with the package's framework integration rather than obviously excessive.
There were no commits and no active maintainers in the last three months, which is a concrete maintenance concern for a package with only three releases.
The repository has two open issues and one open pull request, but no new or closed issues or pull requests in the last month. This is a modest sign of limited current community activity.
Five stars and three forks indicate a small user and contributor footprint. Low popularity is only supporting evidence, but it provides little external maturity signal.
Composer build tooling is present, but no security scanning tools were detected. This is a hygiene gap, not evidence that the release is unsafe on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version ^9.24 | — | — |
symfony/uid Version ^6.4 || ^7.3 | — | — |
doctrine/orm Version ^2.18 || ^3.3 | — | — |
sylius/ui-bundle Version ^2.0 | — | — |
symfony/messenger Version ^6.4 || ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.