The package includes tests and a clear MIT license, but its workflow leaves all three actions unpinned and the repository has no security policy. Organization backing and a matching repository provide some continuity.
62%
Total Score
75
100
83
75
The artifact includes tests, and the repository also contains tests, which supports reliability. However, no README is present for a library that consumers must integrate, creating a documentation gap.
The latest release was published over two years ago, with no releases in the last 12 months. The package has seven releases and a prior release cadence, but current registry maintenance appears stalled.
The repository recorded no commits and had no active maintainers in the last three months. A push in January 2025 shows it was not long-abandoned, but recent maintenance is currently absent.
The linked repository has no security policy, reducing transparency about vulnerability reporting and response. This is a hygiene concern rather than evidence that the release is unsafe.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all three action references are unpinned. The absence of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/api Version ^0.4.0 | — | — |
spryker/api-extension Version ^0.1.0 | — | — |
fond-of-oryx/erp-invoice Version ^3.3.0 | — | — |
spryker/api-query-builder Version ^0.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.