The package has clear documentation, tests, an MIT license, and organization backing. Recent maintenance is quiet, with no releases in the last 12 months and no commits in the last 3 months; the repository also lacks a security policy.
62%
Total Score
67
100
94
50
The project has existed since August 2018 with 62 releases, but it has made no release in the last 12 months, indicating a meaningful slowdown in maintenance.
The repository recorded zero commits and zero active maintainers during the last 3 months, which is direct evidence of currently quiet maintenance.
There are open issues and pull requests, but none were opened, closed, or merged during the last month, consistent with limited recent activity.
The repository has no security policy, leaving vulnerability reporting and disclosure expectations undocumented.
All seven analyzed action references are unpinned, which weakens build reproducibility. The cache-poisoning findings are low-confidence hygiene warnings, and there are no untrusted checkouts, script injections, or write-wide permissions.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sylius/sylius Version ^1.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.