Tests cover the client, Glue, and Zed layers, and the MIT license is present. The workflow is fully auditable but uses three unpinned actions, while no security policy or package README is provided.
58%
Total Score
67
100
79
75
The source repository contains tests, which supports maintainability, but the package has no README and no changelog; the missing changelog is normal packaging practice, while the missing README is a minor consumer-facing gap.
The package has only one release, published about two and a half years ago, with no releases in the last 12 months; this is substantial evidence of limited ongoing maintenance.
There were no commits and no active maintainers in the last three months, which is a meaningful sign that maintenance may have stalled.
No new or closed issues or pull requests were recorded in the last month, and the pull-request count is zero; this provides little evidence of active project support.
The repository uses Make and Composer, showing basic build structure, but no security-scanning tool is configured, leaving a modest transparency and hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/event Version ^1.0.0 || ^2.0.0 | — | — |
spryker/product-list Version ^1.0.0 | — | — |
spryker/uuid-behavior Version ^1.0.0 | — | — |
spryker/glue-application Version ^1.0.0 | — | — |
spryker/glue-application-extension Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.