This report was produced by lockrot.dev on 2026-09-21 from a project created that day out of sylius/sylius-standard, with composer create-project sylius/sylius-standard:v2.2.4 . — nothing was installed, and no script or plugin from any package was run. It is lockrot's output, published by this site.
target PHP data as of lockrot
Priority of the 0 flagged packages
Verdicts across 0 packages
Security advisories

/ to search · j k to move · Enter to open · Esc to close · ? for the glossary. The tab, the filters and the open package are in the address, so the address bar is a link to what you are looking at. Keys: verdict: priority: signal: severity: cve: direct: dev:

What these words mean

full reference

The nine verdicts

Order used by --fail-on and the baseline: abandoned > silent > pinned > left-behind > old-promise > stale > unknown > ok. unknown — a package lockrot could not check — finished and ok are never findings, and none of them fail a build.

The signals

How a priority is reached

The verdict sets a base — abandoned and silent start at critical, pinned, left-behind and old-promise at high, stale at medium. A package nothing requires directly drops one step, one that is only installed for development drops another, and an advisory no release will fix raises it one. Low is the floor, critical the ceiling.