The package has tests, a matching source repository, and clear MIT licensing. Its single release over about 2 years and 8 months ago, no commits in the last 3 months, and fully unpinned workflow actions leave maintenance and build-integrity concerns.
58%
Total Score
75
88
50
There has been only one release, published about 2 years and 8 months ago, with none in the last 12 months. That limited history and long silence make ongoing maintenance uncertain.
The repository recorded zero commits and zero active maintainers in the last 3 months. The repository is not archived, but this does not compensate for the current lack of activity.
The repository has no security policy. That reduces transparency for reporting and handling issues, although the package has tests and a visible source repository.
The only workflow was fully analyzed and has no untrusted checkout or injection findings, but all 3 action references are unpinned. This is a build-hygiene weakness rather than a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/glue-application Version ^1.0.0 | — | — |
spryker/company-business-unit Version ^2.10.0 | — | — |
fond-of-impala/company-user-quote Version ^1.0.0 | — | — |
spryker/glue-application-extension Version ^1.0.0 | — | — |
fond-of-impala/company-business-unit-quote-connector Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.