Setono example plugin for Sylius.
65%
Total Score
caution
Usable with caveats: slow releases and fully unpinned workflow actions limit confidence.
The package has only 2 releases across roughly 20 months, with about 504 days between releases and 1 release in the last 12 months. This suggests slow maintenance, though the latest release is recent and the repository remains active.
All recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown to demonstrate that resilience.
Only 3 commits from 1 active maintainer were recorded in the last 3 months, indicating limited recent maintenance activity. The repository was pushed recently, so this is slowing activity rather than clear abandonment.
The linked repository has no published security policy. This reduces transparency for reporting and handling vulnerabilities, although it does not by itself indicate an unsafe release.
The single workflow was fully analyzed with no dangerous audit findings or untrusted execution paths, but all 22 action references are unpinned. The absent top-level permissions block is acceptable on its own; unpinned actions remain a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.8 | — | — |
sylius/core Version ^1.13 | — | — |
sylius/user Version ^1.13 | — | — |
symfony/uid Version ^6.4 | — | — |
sylius/order Version ^1.13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.