The repository has tests, organizational backing, and is not archived. Its workflow leaves all three actions unpinned, while the repository has no security policy or scanning; maintenance appears inactive since early 2025.
58%
Total Score
75
88
50
The latest release was published in April 2023, with no releases in the last 12 months, indicating a long-standing maintenance gap. The package has four releases and a previously regular cadence, which provides some maturity but does not offset the current inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with stalled maintenance. Its last push was in January 2025, so activity is not entirely absent but is substantially outdated.
No repository security policy was found, and no security-scanning tools were detected. That reduces transparency and the project's visible response process, though it is not evidence of a security defect by itself.
All three analyzed action references are unpinned, which weakens build reproducibility. The audit found no dangerous triggers, untrusted checkouts, script injection, or higher-confidence workflow findings, so this remains a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/company-role Version ^1.0.0 | — | — |
spryker/uuid-behavior Version ^1.0.0 | — | — |
spryker/glue-application Version ^1.0.0 | — | — |
spryker/permission-extension Version ^1.0.0 | — | — |
spryker/company-business-unit Version ^1.0.0 || ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.