Package Health

webgriffe/sylius-akeneo-plugin

The package is clearly licensed, tested, and published with release notes, and its organization-backed repository includes build and static-analysis tooling. Workflow references are not pinned, and the repository does not explicitly connect its name to the package, adding adoption and supply-chain caution.

Latest v3.0.1PackagistPackagist

58%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

50

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

94

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

67

Health Score Breakdown

Repo commit activitydanger

The repository recorded 0 commits and 0 active maintainers in the last 3 months. Combined with the lack of issue and pull-request movement, this is a meaningful maintenance concern despite the recent release history.

Repo issue activitycaution

There were 26 open issues and 7 open pull requests, with no new or closed issues and no merged pull requests in the last 1 month. The unresolved queue indicates limited recent project response.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package. Although a name mismatch can be normal for a subpackage, the lack of any README mention leaves some uncertainty that this repository is the intended source.

Security policycaution

The repository has no security policy, leaving reporting and response expectations unclear. This is a transparency gap, but it is partly offset by the presence of Psalm scanning.

Workflow auditcaution

All 16 analyzed action references are unpinned, and one high-confidence finding identifies use of an archived action; the low-confidence cache findings are hygiene only. Workflows were fully analyzed and had no untrusted checkout or script-injection findings, so this is a caution rather than a severe workflow risk.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
symfony/lock
Version ^6.4 || ^7.4
—
—
cocur/slugify
Version ^4.0
—
—
sylius/sylius
Version ^2.1.2
—
—
guzzlehttp/guzzle
Version ^7.9
—
—
akeneo/api-php-client
Version ^11
—
—

Weekly Downloads

Info

Last Published
6 months ago
Created
6 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform