The MIT license, readable package, tests, and matching Sylius repository support adoption. An organization-backed project and documented security policy add useful transparency.
78%
Total Score
67
100
94
100
The repository recorded zero commits and zero active maintainers in the past three months, which is a maintenance concern despite the recent release.
There were no new or merged pull requests and no issue activity in the past month; this reinforces the recent maintenance slowdown, though open issue data is unavailable.
Composer is used as the build tool, which fits the PHP package, though no security scanning tools were detected.
| Title | Versions | Severity |
|---|---|---|
CVE-2019-12186 sylius/grid is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 1.0.0 - 1.1.19, 1.2.0 - 1.2.18, 1.3.0 - 1.3.13, 1.4.0 - 1.4.5 and 1.5.0 - 1.5.1. | 1.0.0 - 1.1.191.2.0 - 1.2.181.3.0 - 1.3.13 +2 more | Medium |
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^6.4 || ^7.2 || ^8.0 | — | — |
sylius/registry Version ^1.5 | — | — |
webmozart/assert Version ^1.9 | — | — |
symfony/http-kernel Version ^6.4 || ^7.2 || ^8.0 | — | — |
symfony/event-dispatcher Version ^6.4 || ^7.2 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.