The package has a clear MIT license, extensive tests, and no install-time scripts. Its last registry release was over two years ago, with no commits in the past three months, while workflow actions remain unpinned.
57%
Total Score
75
100
86
75
The package has four releases since June 2023, but none in the last 12 months; the latest release was over two years ago. This materially raises maintenance and abandonment concerns.
The repository recorded zero commits and zero active maintainers in the past three months. Combined with the old latest registry release, this is a significant sign of slowed maintenance.
The repository uses Make and Composer, showing a defined build process, but no security-scanning tooling was detected. This is a moderate transparency and maintenance gap.
The repository has no security policy. For a stable library, this weakens vulnerability-reporting transparency but is not severe enough to make the release unfit on its own.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all three action references are unpinned. The missing top-level permissions block is acceptable on its own; unpinned actions remain a reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/event Version ^1.0.0 || ^2.0.0 | — | — |
spryker/search Version ^8.10.0 | — | — |
spryker/customer Version ^4.0.0 || ^5.0.0 || ^6.0.0 || ^7.0.0 | — | — |
spryker/product-list Version ^1.2.0 | — | — |
spryker/event-behavior Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.