The project has a long release history, a recent release with notes, organization backing, tests, and a security policy. Its dependency surface is substantial, so the limited recent activity and workflow pinning deserve attention.
68%
Total Score
63
50
93
100
The package declares 24 runtime dependencies, including framework, persistence, form, and security components. This is a meaningful dependency surface, though not inherently unhealthy.
All 2 recent commits came from one contributor, giving the recent activity a 100% concentration. This increases continuity risk even though the project is organization-owned.
Only 2 commits were recorded in the last 3 months. The recent version release offsets this somewhat, but the observed development pace is light.
There were no new or closed issues or pull requests in the last month, despite 62 open issues and 31 open pull requests. This suggests limited current issue-tracker throughput.
The repository name does not match the package name and its README does not mention the package. Although the repository is organization-owned and the package has a substantial artifact, this weakens the link between the package and its declared source.
| Title | Versions | Severity |
|---|---|---|
CVE-2020-15143 sylius/resource-bundle is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 1.4.0 - 1.4.7, 1.5.0 - 1.5.2, 1.6.0 - 1.6.4 and 1.0.0 - 1.3.14. | 1.0.0 - 1.3.141.4.0 - 1.4.71.5.0 - 1.5.2 +1 more | High |
CVE-2020-15146 sylius/resource-bundle is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 1.4.0 - 1.4.7, 1.5.0 - 1.5.2, 1.6.0 - 1.6.4 and 1.0.0 - 1.3.14. | 1.0.0 - 1.3.141.4.0 - 1.4.71.5.0 - 1.5.2 +1 more | Critical |
CVE-2020-5220 sylius/resource-bundle is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 1.4.0 - 1.4.6, 1.5.0 - 1.5.1, 1.6.0 - 1.6.3 and 1.0.0 - 1.3.13. | 1.0.0 - 1.3.131.4.0 - 1.4.61.5.0 - 1.5.1 +1 more | Medium |
| Dependency | Last Release | Score |
|---|---|---|
symfony/form Version ^6.4 || ^7.4 || ^8.0 | — | — |
symfony/intl Version ^6.4 || ^7.4 || ^8.0 | — | — |
symfony/yaml Version ^6.4 || ^7.4 || ^8.0 | — | — |
symfony/config Version ^6.4 || ^7.4 || ^8.0 | — | — |
symfony/string Version ^6.4 || ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.