It has tests, a README, organization backing, and no install-time scripts. Check the package's licensing and maintenance plans before adopting it.
58%
Total Score
67
81
75
The artifact contains a GPL-3.0 license file, but the manifest declares the package proprietary. This unresolved mismatch creates legal and transparency risk.
The package has 30 releases, but none in nearly two years; the long pause lowers confidence that fixes and compatibility updates will continue.
The repository recorded zero commits and zero active maintainers over the last three months, reinforcing the concern raised by the absence of recent releases.
There is one open issue but no issues or pull requests were opened or closed in the last month, providing little evidence of current maintenance.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/log Version ^3.0.0 | — | — |
spryker/kernel Version ^3.0.0 | — | — |
spryker/search Version >=8.9.0 | — | — |
guzzlehttp/guzzle Version ^6.0.0|^7.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.