The repository includes tests and the package has a clear MIT license. Its workflow uses three unpinned actions and has no security scanning, adding maintenance and build-integrity concerns.
62%
Total Score
75
88
75
The package has eight releases since June 2021, but its latest release was about 18 months ago and there were no releases in the last 12 months. This indicates materially slowed maintenance.
The repository had no commits and no active maintainers during the last three months. The non-archived repository and existing release history provide some context, but current maintenance is not evident.
The project uses Make and Composer, but no security scanning tools were detected. That is a transparency and maintenance gap for a package with substantial runtime dependencies.
The sole workflow was fully analyzed with no dangerous triggers or audit findings, but all three referenced actions are unpinned. This leaves build inputs less reproducible than they could be.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/log Version ^1.0.0 || ^2.0.0 || ^3.0.0 | — | — |
spryker/oms Version ^6.0.0 || ^7.0.0 || ^8.0.0 || ^10.0.0 || ^11.0.0 | — | — |
spryker/sales Version ^8.0.0 || ^10.0.0 || ^11.0.0 | — | — |
spryker/store Version ^1.1.0 | — | — |
spryker/payment Version ^3.0.0 || ^4.0.0 || ^5.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.