The release is stable, licensed, tested, and backed by an organization. However, the repository has no commits in three months, does not mention this package, and uses 12 unpinned actions. Pin this version only if the repository identity and maintenance status are confirmed.
58%
Total Score
75
88
50
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful maintenance concern for a payment integration.
The repository name does not match the package name and its README does not mention the package, so the link may be incorrect or the package may be piggy-backing on another project.
The project uses Composer and Make, but no security-scanning tooling was detected, leaving a modest transparency and maintenance gap.
All 12 analyzed action references are unpinned, weakening build reproducibility. The reported cache-poisoning findings are low-confidence hygiene alerts and do not independently establish a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sylius/sylius Version ^2.0.4 | — | — |
symfony/webpack-encore-bundle Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.