The package includes thorough documentation, tests, a changelog, and a license, while its repository remains active rather than archived. Its registry release is over five years old, recent commit activity is absent, and the repository has no security policy; all workflow actions are also unpinned.
55%
Total Score
50
100
86
75
The latest registry release was published over five years ago, with no releases in the last 12 months. Earlier releases were fairly regular, but the long current gap raises maintenance and compatibility risk.
The repository recorded zero commits and zero active maintainers in the last three months. This conflicts with its recent push date and leaves current maintenance capacity uncertain.
No security policy was found in the repository, reducing transparency for reporting and handling vulnerabilities in an administrative order-management plugin.
All 7 analyzed action references are unpinned, which weakens build reproducibility. The reported cache-poisoning findings have low confidence, so they are hygiene concerns rather than severe evidence on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sylius/sylius Version ~1.9.0 | — | — |
friendsofsymfony/jsrouting-bundle Version ^2.2 | — | — |
friendsofsymfony/oauth-server-bundle Version >2.0.0-alpha.0 ^2.0@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.