The repository includes tests, a matching README, and a clear MIT license, while organization backing adds some continuity. Workflow auditing found no dangerous patterns, but all three action references are unpinned.
60%
Total Score
75
100
88
67
This package has only one release, published nearly two years ago, with no releases in the last 12 months. That limits evidence of ongoing maintenance and makes adoption more dependent on the existing release remaining adequate.
There were no commits and no active maintainers in the last three months. Combined with the single-release history, this is a meaningful maintenance concern.
The project uses Composer and Make, but no security-scanning tools were detected. This is a transparency and hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy. For a maintained integration library this weakens vulnerability-reporting transparency, though organization backing and repository tests provide some compensation.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all three action references are unpinned, leaving a modest reproducibility and maintenance-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/permission Version ^1.0.0 | — | — |
spryker/permission-extension Version ^1.0.0 | — | — |
spryker/company-business-unit Version ^1.0.0 || ^2.0.0 | — | — |
fond-of-impala/company-user-reference-quote-connector Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.