Jellyfish Gift Card Module.
63%
Total Score
caution
Usable with caveats: the latest release is more than three years old.
The package has only three releases and none in the last three years, with the latest release more than three years old. This materially raises staleness risk despite the repository being pushed more recently.
There were no commits and no active maintainers in the last three months. The 2025 push shows the repository was not abandoned long ago, but current activity remains a maintenance concern.
The repository uses Make and Composer, showing build tooling, but no security scanning tools were detected. This is a modest transparency and maintenance weakness.
No repository security policy was found, leaving vulnerability reporting and response expectations unclear.
All three workflow action references are unpinned, weakening build reproducibility and supply-chain hygiene. The audit found no dangerous triggers, untrusted checkouts, script injection, or high-severity findings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spryker/log Version ^1.0.0 || ^2.0.0 || ^3.0.0 | — | — |
spryker/oms Version ^6.0.0 || ^7.0.0 || ^8.0.0 || ^10.0.0 || ^11.0.0 | — | — |
spryker/sales Version ^8.6.0 || ^10.0.0 || ^11.0.0 | — | — |
spryker/guzzle Version ^2.0.0 | — | — |
spryker/glossary Version ^3.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.