The package has a clear license, repository tests, release notes, and organizational backing. Its alpha status and limited recent activity warrant pinning this exact version and monitoring for a maintained follow-up.
52%
Total Score
75
86
50
The package has 19 releases since September 2019, but none in the last 12 months; the latest release was about 13 months ago. This weakens confidence in ongoing maintenance.
There were zero commits and zero active maintainers in the last three months, consistent with the absence of releases in the last year. This is a meaningful maintenance concern for an alpha package.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap, though it is not evidence of unsafe code.
The assessed release is explicitly an alpha version, so compatibility and behavior may still change despite the package having a stable major version designation.
All 20 analyzed action references are unpinned, and the audit found a high-confidence template-injection issue. The workflows had no untrusted checkout or dangerous trigger, so this is workflow hygiene and supply-chain caution rather than a standalone severe verdict.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^2.15 || ^3.8 | — | — |
sylius/core Version ^2.0 | — | — |
doctrine/orm Version ^2.18 || ^3.3 | — | — |
symfony/form Version ^6.4 || ^7.3 | — | — |
doctrine/dbal Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.