Netgen Layouts & Sylius eCommerce integration
68%
Total Score
caution
Usable with caveats: one maintainer and high-confidence unpinned workflow images weaken otherwise active maintenance.
All 8 analyzed action references are unpinned, and the audit found a high-confidence, high-severity unpinned container image in a workflow. The workflows have no untrusted checkout or script-injection trigger, which limits the risk but does not remove reproducibility concerns.
All 3 recent commits came from one contributor, concentrating current maintenance capacity and increasing continuity risk if that contributor becomes unavailable.
Composer build tooling is present, but no security scanning tools were detected, leaving a gap in the project's visible automated security hygiene.
The repository has no security policy, so the process for reporting and handling vulnerabilities is not documented for consumers or contributors.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.6 | — | — |
sylius/sylius Version ^2.2 | — | — |
netgen/layouts-core Version ~2.0.0 | — | — |
sylius/resource-bundle Version ^1.14 | — | — |
netgen/layouts-standard Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.