The repository includes tests and clearly matches the package, with organizational backing and no install-time scripts. The absent security policy and three unpinned workflow actions reduce transparency and build reproducibility; pin version 1.0.1 if adopting it.
55%
Total Score
67
100
81
83
The package has had only three releases, all within about one week, and none in the last two years. This strongly suggests maintenance has paused, despite the short initial release cadence.
There were zero commits and zero active maintainers in the last three months, consistent with more than two years since the last push. This is strong evidence of a maintenance pause.
The project uses Make and Composer, which supports repeatable development workflows. No security scanning tools are present, leaving a modest hygiene gap.
The repository has no security policy, reducing transparency about vulnerability reporting and maintenance expectations. This is a genuine but non-severe gap alongside the broader maintenance concerns.
The only workflow was fully analyzed with no dangerous triggers, injection findings, or audit findings. However, all three action references are unpinned, which weakens build reproducibility, while the lack of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/customers-rest-api Version ^1.10.0 | — | — |
fond-of-kudu/customer-password-updated-at-connector Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.