The package has had no release or repository activity for roughly four years, and all seven workflow actions are unpinned. It remains licensed, tested, non-archived, and backed by a matching organization repository.
58%
Total Score
50
100
94
67
There were no commits and no active maintainers in the last three months, consistent with the long release pause and materially increasing maintenance risk.
The latest release was about four years ago, with no releases in the last 12 months; eight releases show an established history, but the long pause raises abandonment risk.
No repository security policy was found. This is a transparency gap for an integration package, but it is secondary to the stronger maintenance evidence.
The sole workflow was fully analyzed with no untrusted triggers or injection sinks. However, all seven action references are unpinned; the reported cache-poisoning findings are low-confidence hygiene warnings and do not independently establish severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/flex Version ^1.10 | — | — |
sylius/sylius Version ~1.10.0 || ~1.11.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.