Clear licensing, tests, release notes, and security scanning improve day-to-day confidence. Treat the release-candidate status and workflow hygiene as reasons to pin deliberately rather than adopt blindly.
78%
Total Score
100
100
94
67
No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented.
This is a release candidate, and 65% of recent releases are prereleases, so consumers should expect some stability risk despite a stable major version.
All nine analyzed action references are unpinned, and two workflows use high-confidence secrets-inherit findings; there are no untrusted checkouts or injection findings, but the workflow setup needs tightening.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/lock Version ^6.4|| ^7.2 | — | — |
sylius/sylius Version ^2.0 | — | — |
symfony/asset Version ^6.4|| ^7.2 | — | — |
symfony/validator Version ^6.4|| ^7.2 | — | — |
payplug/payplug-php Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.