The MIT license, matching repository, README, and test suite provide useful transparency for integrating the module. Unpinned workflow actions and no repository security scanning add modest maintenance risk.
58%
Total Score
75
88
75
The package has only 3 releases since June 2022, with none in the last 12 months and the latest released in February 2023. This is a meaningful sign of reduced maintenance, despite the repository having been pushed more recently.
There were 0 commits and 0 active maintainers in the last three months. Combined with the stale registry release history, this raises maintenance and abandonment concerns.
The repository uses Composer and Make, but no security scanning tools were detected. This is a modest transparency and maintenance gap, not a severe risk by itself.
The repository has no security policy. For a REST API module, this leaves vulnerability-reporting expectations unclear and modestly lowers transparency.
The workflow audit completed without detected dangerous findings or untrusted triggers, but all 3 action references are unpinned. The missing top-level permissions block is acceptable on its own, so the main concern is reproducibility and action supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/api Version ^0.4.0 | — | — |
spryker/api-extension Version ^0.1.0 | — | — |
spryker/api-query-builder Version ^0.1.0 | — | — |
fond-of-oryx/company-product-list-connector Version ^1.1.0 || ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.