The repository includes tests, release notes, and automated security tooling. Its license wording and workflow setup reduce transparency and make ongoing maintenance less dependable.
58%
Total Score
50
80
50
The manifest declares the package proprietary while the repository license file is recognized as MIT. The repository is licensed, but the mismatch creates avoidable uncertainty for adopters.
The package has only two releases, with the latest in November 2023 and none in the last 12 months; this is a meaningful maintenance concern for a framework plugin.
The repository recorded zero commits and zero active maintainers in the last three months, indicating that maintenance may have stalled even though the repository is not archived.
The repository has no security policy, which leaves vulnerability reporting and response expectations undocumented for consumers.
All seven analyzed action references are unpinned, reducing build reproducibility. The cache-poisoning findings are low-confidence hygiene warnings, so they add limited weight rather than indicating a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sylius/sylius Version ^1.12 | — | — |
sylius/mailer-bundle Version ^1.8 || ^2.0@beta | — | — |
symfony/webpack-encore-bundle Version ^1.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.