Package Health

3brs/sylius-enterprise-security-plugin

The repository has substantial recent work, three active contributors, tests, and an organization behind it. CI still uses six unpinned actions and installs packages outside a lockfile, while the project has no security policy.

Latest v1.0.0PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

83

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

50

Health Score Breakdown

Lifecycle scriptscaution

Composer runs post-create, post-install, and post-update scripts. Install-time scripts can affect dependency installation and deserve review, although this signal alone does not show harmful behavior.

Release historycaution

This package is brand new, with one release published today and no established release cadence. The active repository partly offsets the limited registry history, but version maturity remains unproven.

Repo toolingcaution

The project uses Composer and Make, but no security scanning tools were detected. That is a modest transparency and maintenance gap for a security-focused plugin.

Security policycaution

No repository security policy was found. For a plugin covering authentication, passkeys, OAuth, and account protection, the absence of a documented vulnerability-reporting path is a real transparency gap.

Workflow auditcaution

CI analyzed completely and has no untrusted checkout or script-injection findings, but all six action references are unpinned and two high-confidence checks install packages outside a lockfile. These are workflow hygiene and reproducibility concerns, not severe risks on their own.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

3BRS

Direct Dependencies

DependencyLast ReleaseScore
psr/clock
Version ^1.0
sylius/sylius
Version ^2.1
symfony/clock
Version ^6.4|^7.4
scheb/2fa-totp
Version ^7.13
endroid/qr-code
Version ^6.0

Weekly Downloads

Info

Last Published
2 days ago
Created
2 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform