Organization backing and a real test suite support the package, but recent commit activity is absent and releases stopped in January 2023. The workflow is complete yet all three actions are unpinned, adding a smaller supply-chain hygiene concern.
64%
Total Score
75
88
75
Only two releases exist, with none in the last 12 months and the latest published in January 2023; this indicates a meaningful maintenance slowdown for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, despite not being archived and having a push in January 2025. That recent inactivity lowers confidence in ongoing maintenance.
The project uses Make and Composer, providing build structure, but no security-scanning tooling was detected. That is a modest transparency and hygiene gap rather than a severe risk.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. Organization backing partially offsets the concern but does not remove it.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all three action references are unpinned. The missing top-level permissions block is acceptable on its own; unpinned actions remain a supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/company Version ^1.0.0 | — | — |
spryker/util-encoding Version ^1.0.0 || ^2.0.0 | — | — |
spryker/util-sanitize Version ^1.0.0 || ^2.0.0 | — | — |
spryker/company-gui-extension Version ^1.0.0 | — | — |
fond-of-oryx/company-product-list-connector Version ^1.0.0 || ^2.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.