The repository has tests, an MIT license, and organization backing, but it lacks a security policy and uses three unpinned workflow actions. These hygiene strengths do not offset the long inactivity gap.
58%
Total Score
75
100
86
75
This is the only release, published over two years ago, with no releases in the last 12 months. That materially raises abandonment and compatibility risk.
There were no commits and no active maintainers in the last three months, consistent with a project that has seen little recent maintenance.
The repository uses Make and Composer, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap.
No security policy was found, leaving vulnerability-reporting expectations undocumented. This is a hygiene concern, not evidence that the package is unsafe.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all three action references are unpinned, leaving avoidable build-reproducibility risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/quote Version ^2.0.0 | — | — |
spryker/uuid-behavior Version ^1.0.0 | — | — |
fond-of-impala/company-user-reference Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.