The project has a long release history, current stable version, tests, release notes, and organizational backing. Recent repository activity is paused, and all 11 workflow actions are unpinned; the missing security policy adds a smaller transparency concern.
68%
Total Score
67
100
100
50
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Although the release history is healthy, this recent pause is a real maintenance concern.
There were no new issues or closed issues in the last month, with only one merged pull request and 17 open issues. This suggests limited recent project interaction, though it is less concerning than the absent commits.
The repository has no security policy. That weakens vulnerability-reporting transparency, but it is a moderate documentation gap rather than evidence of abandonment by itself.
All 3 workflows were fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 11 action references are unpinned, leaving build inputs exposed to upstream changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sylius/sylius Version ~2.0 | — | — |
league/commonmark Version ^2.6 | — | — |
twig/extra-bundle Version ^3.13 | — | — |
twig/markdown-extra Version ^3.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.