QuadPay payment plugin for Sylius applications.
58%
Total Score
caution
Usable with caveats: no commits or releases since September 2024 leave maintenance uncertain.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the roughly 2-year gap since the latest release. This raises abandonment risk.
The package has existed since 2018 and has 8 releases, but it has had no release in the last 12 months; the latest release was about 2 years ago. This is a meaningful maintenance concern despite its established history.
The project uses Composer, but no security scanning tools were detected. For a payment integration, that is a transparency and maintenance gap.
The repository has no security policy. This makes vulnerability reporting and response expectations less clear, particularly for a payment-related plugin.
All 7 analyzed action references are unpinned, which weakens build reproducibility. The reported cache-poisoning findings are low-confidence hygiene warnings and do not independently establish a severe workflow risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sylius/sylius Version ~1.12.0 || ~1.13.0 | — | — |
php-http/message-factory Version ^1.1 | — | — |
symfony/webpack-encore-bundle Version ^1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.