It has a long release history, recent commits from two maintainers, and clear tests, documentation, and licensing. Organization backing and dependency scanning add useful support.
78%
Total Score
100
100
50
The repository has no published security policy, leaving vulnerability reporting and response expectations less transparent.
All six analyzed action references are unpinned, which weakens build reproducibility. The cache-poisoning findings are low-confidence hygiene observations, with no untrusted checkout or script-injection path detected.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
sylius/sylius Version ~2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.