Recent releases, repository tests, and organizational ownership provide useful maintenance support. The beta status, one-person recent commit base, and workflow audit findings leave meaningful adoption risk.
62%
Total Score
88
50
88
50
Both workflows use 27 unpinned actions, and the audit found one high-confidence template-injection issue; although no untrusted checkout or write-wide token trigger was reported, this remains a significant workflow hygiene and supply-chain concern.
The package declares 27 runtime dependencies across Sylius, Symfony, and Meta integrations, creating substantial compatibility surface; this is partly explained by its role as a Sylius plugin.
All 14 recent commits came from one contributor, concentrating maintenance knowledge and increasing continuity risk; organization backing provides some handoff capacity but does not remove the concentration.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest process gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
sylius/core Version ^1.0 | — | — |
sylius/order Version ^1.0 | — | — |
symfony/form Version ^6.4 | — | — |
sylius/locale Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.