Workflow and documentation hygiene need attention. The organization backing, tests, license, and stable version support adoption, but no releases in over two years and no commits in the last three months raise maintenance concerns.
58%
Total Score
75
86
67
The package contains tests and the repository contains corresponding test files, which supports maturity; the missing package README is a minor consumer-documentation gap for a library.
The package has had no release in over two years, despite nine releases overall; this materially raises abandonment risk even though its earlier release cadence was active.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the latest release and suggesting limited current maintenance.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented; the package's tests and organization backing provide some compensating project structure but not a reporting path.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings, but all three action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/event Version ^2.3.0 | — | — |
spryker/queue Version ^1.0.0 | — | — |
spryker/search Version ^8.10.0 | — | — |
spryker/customer Version ^4.0.0 || ^5.0.0 || ^6.0.0 || ^7.0.0 | — | — |
spryker/event-behavior Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.