The source repository is unarchived, backed by an organization, and includes tests, release notes, and dependency scanning. Its workflow leaves all three actions unpinned, and no security policy is published.
64%
Total Score
83
100
93
50
The package has had 9 releases since June 2024, but none in the last 12 months; this indicates a meaningful maintenance slowdown despite its previously regular release interval.
No commits or active maintainers were recorded in the last 3 months, a direct sign of weak recent development activity despite the repository's recent push timestamp.
The repository has no published security policy, leaving vulnerability reporting and response expectations less transparent.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all 3 action references are unpinned, making build inputs less reproducible and easier to change unexpectedly.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sylius/sylius Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.