The source remains active enough to be traceable, with an unarchived organization-owned repository and matching package references. Tests, an MIT license, and no install scripts support adoption, while workflow references are not pinned and security guidance is absent.
58%
Total Score
75
86
75
The package has had only two releases, with the latest in September 2023 and none in the following 12 months; this is a meaningful maintenance concern for a dependency.
There were no commits and no active maintainers in the measured three-month period, reinforcing the concern raised by the old latest release and indicating limited recent maintenance.
The repository uses Make and Composer build tooling, but no security scanning tools were detected; this is a modest transparency and maintenance gap.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
All three analyzed action references are unpinned, which weakens build reproducibility. The audit found no untrusted checkout, script injection, high-confidence findings, or incomplete analysis, so this remains a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/company Version ^1.0.0 | — | — |
fond-of-impala/price-list Version ^1.0.0 | — | — |
fond-of-spryker/company-extension Version dev-master | — | — |
fond-of-oryx/company-user-search-rest-api Version ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.