Tests, licensing, and organization ownership provide a solid project foundation. The repository has no recent commit or issue activity, while workflow references are all unpinned and no security policy or scanning is present.
58%
Total Score
75
79
75
The package has only two releases, with the latest on January 23, 2023 and none in the following roughly three years and eight months; this materially raises abandonment risk.
There were zero commits and zero active maintainers in the last three months, and the last push was January 15, 2025; this indicates substantially slowed maintenance.
Composer and Make are used for project tooling, but no security scanning tools are configured, leaving a modest transparency and maintenance gap.
The repository has no security policy, reducing guidance for reporting and handling vulnerabilities, though this is less serious than the clear maintenance slowdown.
The single workflow was fully analyzed with no dangerous findings, but all three action references are unpinned; missing top-level permissions is acceptable here, while unpinned actions remain a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/customer Version ^6.0.0 || ^7.0.0 | — | — |
spryker/auth-rest-api-extension Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.