Maintenance has been quiet since the last registry release, and the repository has no security policy. The package is licensed, tested, organization-backed, and not archived, which reduces adoption risk.
57%
Total Score
75
100
81
67
The package contains tests and the repository contains tests, which supports maintainability. The missing README is a minor consumer-documentation gap for a library, while the absent changelog is expected packaging practice.
The package has only two releases, with none in the last 12 months; the latest release was over three years ago. This points to limited ongoing maintenance, although the stable 2.0.0 version remains available.
There were no commits and no active maintainers in the three months measured. This is meaningful evidence of currently quiet maintenance, despite the repository not being archived.
The repository uses Make and Composer, but no security scanning tools were detected. The build setup is present; the missing scanning is a modest transparency and maintenance concern.
No security policy was found in the repository. For a small connector library this is a hygiene gap rather than evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fond-of-spryker/brand-company Version dev-master | — | — |
fond-of-oryx/brand-product-list-connector Version ^1.0.0 || ^2.0.0 | — | — |
fond-of-oryx/company-product-list-connector-extension Version ^1.0.0 || ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.