Tests and release notes provide useful coverage, and the repository is not archived. The fully unpinned workflow and absent security policy add smaller maintenance concerns.
42%
Total Score
75
83
50
The package includes a substantial README, tests, and release notes, but the README explicitly says the repository is deprecated, will not be maintained, and will receive no bug fixes. The tests and release notes provide some compensation but do not remove the abandonment risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although the release history shows recent releases, the current source activity provides weak evidence of ongoing maintenance.
The linked repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a transparency gap, but it is secondary to the explicit maintenance warning.
All 7 analyzed action references are unpinned, which weakens build reproducibility. The cache-poisoning findings are low-confidence hygiene warnings and do not independently establish a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sylius/sylius Version ~1.14.0 | — | — |
symfony/webpack-encore-bundle Version ^1.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.