Documentation, tests, and an MIT declaration provide useful adoption and maintenance context. Workflow hygiene is weak, with all 10 actions unpinned and one archived action, while the repository shows no recent development.
43%
Total Score
67
94
75
The package has only two releases, with the latest published in January 2023 and none in the following three years. This is strong evidence of abandonment risk, although the repository is not archived.
There were zero commits and zero active maintainers in the last three months. Combined with the old latest release, this materially increases the risk that compatibility issues will remain unresolved.
There were no new or merged pull requests and no issue activity in the last month. This is consistent with the broader signs of inactivity, although the open-issue count is unknown.
The repository has no security policy. This weakens vulnerability-reporting transparency, though it is a secondary concern compared with the maintenance evidence.
All 10 analyzed action references are unpinned, and a high-confidence audit finding identifies an archived action; both weaken workflow supply-chain hygiene. The cache-poisoning findings are low confidence and do not materially change the assessment.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 | — | — |
doctrine/orm Version ^2.7 | — | — |
symfony/form Version ^4.4 || ^5.2 | — | — |
doctrine/dbal Version ^2.13 | — | — |
sylius/sylius Version ^1.8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.