The repository is small but has tests and a clear MIT license. Unpinned workflow actions and no security policy add modest transparency and upkeep concerns.
58%
Total Score
83
81
75
The source repository includes tests, which supports basic project maturity. The package has no README, leaving consumer-facing guidance less transparent for a library.
This package has only one release, published about 2 years 11 months ago, with no releases in the last 12 months. That gives little evidence of ongoing release maintenance.
There were no commits and no active maintainers in the last 3 months. Combined with the single old release, this raises abandonment and upkeep concerns.
The repository uses Composer and Make, showing some build structure, but no security scanning tooling was detected. This is a modest repository-hygiene gap rather than a severe risk.
No security policy was found in the repository, reducing transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/permission Version ^1.0.0 | — | — |
spryker/company-role Version ^1.0.0 | — | — |
spryker/company-user Version ^1.0.0 || ^2.0.0 | — | — |
spryker/permission-extension Version ^1.0.0 | — | — |
fond-of-oryx/cart-search-rest-api-extension Version ^1.0.0 || ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.