Package Health

sylius/resource-bundle

The project has a long release history, a recent release with notes, organization backing, tests, and a security policy. Its dependency surface is substantial, so the limited recent activity and workflow pinning deserve attention.

Latest v1.14.2PackagistPackagist

68%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

63

Dependencies
Dependencies
Evaluates the health and security of package dependencies

50

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

93

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Are you affected? Scan for Free

Health Score Breakdown

Dependency profilecaution

The package declares 24 runtime dependencies, including framework, persistence, form, and security components. This is a meaningful dependency surface, though not inherently unhealthy.

Repo bus factorcaution

All 2 recent commits came from one contributor, giving the recent activity a 100% concentration. This increases continuity risk even though the project is organization-owned.

Repo commit activitycaution

Only 2 commits were recorded in the last 3 months. The recent version release offsets this somewhat, but the observed development pace is light.

Repo issue activitycaution

There were no new or closed issues or pull requests in the last month, despite 62 open issues and 31 open pull requests. This suggests limited current issue-tracker throughput.

Repo package mentioncaution

The repository name does not match the package name and its README does not mention the package. Although the repository is organization-owned and the package has a substantial artifact, this weakens the link between the package and its declared source.

Vulnerabilities

TitleVersionsSeverity
CVE-2020-15143
sylius/resource-bundle is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 1.4.0 - 1.4.7, 1.5.0 - 1.5.2, 1.6.0 - 1.6.4 and 1.0.0 - 1.3.14.
1.0.0 - 1.3.141.4.0 - 1.4.71.5.0 - 1.5.2 +1 more
High
CVE-2020-15146
sylius/resource-bundle is vulnerable to Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in versions 1.4.0 - 1.4.7, 1.5.0 - 1.5.2, 1.6.0 - 1.6.4 and 1.0.0 - 1.3.14.
1.0.0 - 1.3.141.4.0 - 1.4.71.5.0 - 1.5.2 +1 more
Critical
CVE-2020-5220
sylius/resource-bundle is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 1.4.0 - 1.4.6, 1.5.0 - 1.5.1, 1.6.0 - 1.6.3 and 1.0.0 - 1.3.13.
1.0.0 - 1.3.131.4.0 - 1.4.61.5.0 - 1.5.1 +1 more
Medium

Package versions

Maintainers

Paweł Jędrzejewski
Sylius project
Community contributions

Direct Dependencies

DependencyLast ReleaseScore
symfony/form
Version ^6.4 || ^7.4 || ^8.0
symfony/intl
Version ^6.4 || ^7.4 || ^8.0
symfony/yaml
Version ^6.4 || ^7.4 || ^8.0
symfony/config
Version ^6.4 || ^7.4 || ^8.0
symfony/string
Version ^6.4 || ^7.4 || ^8.0

Weekly Downloads

Info

Last Published
3 months ago
Created
13 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform