Strong tests, clear MIT licensing, and organization ownership provide useful maintenance context. The missing security policy and unpinned workflow actions weaken transparency and build hygiene.
58%
Total Score
75
75
75
The package has had no release in nearly three years, with zero releases in the last 12 months. Its three-release history provides some evidence of a real project, but the long gap raises abandonment concern.
The source repository contains tests, which supports basic project maturity. The published artifact has no README, reducing consumer documentation for a library package, while the absent changelog is normal packaging practice.
The repository recorded no commits and no active maintainers in the last three months. A push in November 2024 shows the repository was not always dormant, but current activity is weak.
The project uses Make and Composer, showing a basic build structure, but no security-scanning tooling was detected. That is a modest transparency and maintenance gap.
The repository has no security policy. This does not show a defect in the package, but it leaves vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/api Version ^0.4.0 | — | — |
spryker/product Version ^6.4.0 | — | — |
spryker/api-extension Version ^0.1.0 | — | — |
spryker/api-query-builder Version ^0.1.0 | — | — |
fond-of-impala/conditional-availability Version ^1.1.0 || ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.