The release is clearly licensed, documented, tested, and backed by an organization with a security policy. Its dependency set is moderate, but the recent repository activity is quiet and the repository does not explicitly identify this package.
68%
Total Score
75
100
86
100
The repository recorded no commits and no active maintainers during the last three months, a real maintenance concern despite the recent push timestamp shown by the archive-status signal.
The repository name does not match the package name and its README does not mention the package, so the linkage is less transparent even though the organization backing is consistent.
Composer build tooling is present, but no repository security-scanning tool was detected, leaving a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sylius/product Version ^2.0 | — | — |
sylius/locale-bundle Version ^2.0 | — | — |
sylius/resource-bundle Version ^1.14.2 | — | — |
sylius/attribute-bundle Version ^2.0 | — | — |
symfony/framework-bundle Version ^6.4.1 || ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.